Hackers Exploit BNB Chain to Distribute Malware
Microsoft has issued a warning about hackers exploiting BNB Chain to distribute malware. The attackers compromise legitimate websites and inject malicious JavaScript code that connects with smart contracts on the BNB Smart Chain network.
The campaign uses the technique known as EtherHiding, linked to the ClearFake malware group. This decentralized design makes the attacker's network more resilient to removal or takedown attempts.
Cybercriminals present users with a fake CAPTCHA that asks them to open the Windows 'Run' command window and paste text from the clipboard into a command prompt. The malicious script then contacts a BNB Smart Chain RPC node to obtain the next layer of the payload.