BNB Chain Malware Campaign Targets Windows Users, Exploits Infrastructure
Microsoft has identified a malware campaign that exploits BNB Chain infrastructure to distribute malicious code through compromised websites. The operation uses Base64-encoded JavaScript and bypasses traditional website protections, increasing the risk of successful infections for both businesses and consumers.
The attackers disguise their harmful commands as routine security checks, tricking visitors into running them. This allows them to leverage EtherHiding/ClearFake techniques and contact BNB Smart Chain RPC gateways to query smart contracts.
According to Microsoft Threat Intelligence, a cluster of compromised websites is displaying ClickFix lures and using EtherHiding, a technique associated with the ClearFake campaign. This highlights how cybercriminals are adapting blockchain technology for malicious purposes instead of legitimate innovation.