#BNB Chain security risk#Malware distribution risk
Hackers Use BNB Chain Smart Contracts to Distribute Malware via EtherHiding
WooFun2026-08-07 10:12
Key Takeaways
Microsoft Threat Intelligence identifies a campaign where ClearFake exploits BNB Chain smart contracts for malware distribution. Attackers use fake CAPTCHAs to deploy stealers like Lumma, urging users to restrict command-line utilities to mitigate risk.
Woofun AI reports that Microsoft Threat Intelligence has identified a sophisticated malware distribution campaign leveraging the BNB Chain, attributed to the ClearFake malware group. The operation utilizes a technique termed EtherHiding, embedding malicious code within smart contracts to bypass traditional security perimeters. This marks a significant shift in how cybercriminals exploit decentralized infrastructure for persistent threat delivery.
The technical execution began on August 6, 2026, with attackers compromising legitimate websites to inject JavaScript scripts. These scripts establish connections with smart contracts hosted on the BNB Smart Chain RPC node, creating a decentralized persistence mechanism. Because content recorded in these contracts can only be edited or removed by the private key of the wallet owner, the attacker’s network remains largely invulnerable to standard takedown attempts or governmental intervention.
To finalize the infection, the campaign employs a browser-based social engineering vector centered on a fake CAPTCHA. Victims are instructed to open the Windows "Run" command window and paste text from their clipboard, which contains obfuscated attack code. This method abuses native operating system tools, including PowerShell, Command Prompt, Windows Terminal, mshta, and curl, to execute the payload while hiding its components through complex obfuscation techniques.
Woofun AI data shows that successful execution exposes systems to diverse malware families, including Lumma Stealer, XWorm, AsyncRAT, and MintsLoader. These payloads facilitate massive credential extraction and pave the way for manually operated ransomware attacks. In response, Microsoft advises organizations to restrict unnecessary command-line utilities and enable detailed PowerShell logging to detect such activities early.
This incident follows previous warnings from Microsoft regarding threats in the crypto ecosystem. In June of last year, the company disclosed a "crypto clippers" campaign that modified wallet addresses copied to the clipboard. Earlier, researchers revealed a large-scale cryptojacking network utilizing SEO poisoning, highlighting the constant evolution of threats targeting decentralized digital environments.
Comments
No comments yet.