Microsoft's threat analysis service has uncovered a new method of cyberattack in which malicious actors use smart contracts on the $BNB blockchain to distribute malware instructions.
According to Microsoft, attackers are using the "EtherHiding" method on compromised websites. In this method, instead of receiving malicious instructions directly from a classic server controlled by the attackers, they are retrieved from a smart contract on the $BNB Smart Chain network via an RPC gateway.
A key element of the attack chain are fake CAPTCHA screens. These pages, designed to give users the impression of a real verification, instruct them to press Windows + R, then paste a pre-prepared command from the clipboard using Ctrl + V, and finally press Enter. In this way, the user, unsuspectingly, executes malicious commands prepared by the attackers on their computer.
Microsoft stated that this method is particularly frequently used in social engineering campaigns known as ClickFix and TerminalFix. According to the company, these campaigns target thousands of corporate and personal devices daily worldwide.
Using blockchain infrastructure as part of the attack chain allows the attackers to update instructions through a distributed and publicly accessible infrastructure, rather than through a centralized server. This also represents a new method that may make detecting and completely disabling the malicious infrastructure more difficult.
*This is not investment advice.
end-content







