BNB Chain Smart Contracts Used in Sophisticated Malware Operation
Microsoft has uncovered a sophisticated malware operation that uses smart contracts on the BNB Chain to deliver attack instructions to thousands of compromised Windows devices worldwide every day.
The campaign, which combines fake CAPTCHA verification prompts with blockchain infrastructure, makes it exceptionally difficult for security teams to remove the malicious commands.
The technique, known as EtherHiding, stores attacker instructions inside a blockchain smart contract rather than on a traditional server. When a visitor lands on a compromised website, injected JavaScript contacts a BNB Smart Chain RPC gateway and retrieves commands from a contract previously linked to the ClearFake malware campaign.
Victims encounter a fraudulent CAPTCHA page that instructs them to open the Windows Run dialog, paste text from their clipboard, and press Enter. The clipboard content has already been prepared by the attackers, and executing it immediately runs a malicious command on the target system.