BNB Chain Compromised: Hackers Spread Malware Through Fake CAPTCHAs
Hackers are using BNB Chain contracts to spread malware through compromised websites and fake CAPTCHA prompts, according to Microsoft Threat Intelligence.
The campaign uses EtherHiding, a technique that stores malicious instructions in a blockchain smart contract. JavaScript injected into compromised websites contacts a BNB Chain gateway and retrieves commands from a contract previously linked to ClearFake, a malware campaign that infects legitimate websites.
Visitors to compromised websites see a fake CAPTCHA telling them to open the Windows Run dialog, paste text from their clipboard, and press Enter. Doing so runs a command supplied by the attacker.
The method, known as ClickFix, depends on victims executing the malware themselves. A variation called TerminalFix directs users to Windows Terminal or PowerShell.