BNB Chain Smart Contracts Used to Hide Malware Attack Commands
Microsoft has identified a widespread malware campaign that uses BNB Chain smart contracts to store and retrieve attack instructions. This technique, dubbed 'EtherHiding,' is used by attackers to evade detection and disrupt traditional disruption tactics such as server seizures.
The operation affects thousands of Windows systems daily, spanning both corporate networks and individual users. Attackers present victims with counterfeit CAPTCHA challenges that urge them to open the Windows Run dialog or PowerShell, pasting pre-loaded clipboard content and executing it.
Once the command runs, the malware abuses legitimate Windows components such as PowerShell, cmd, and scheduled tasks. The observed payloads include credential theft tools like Lumma Stealer, remote-access tools such as Xworm and AsyncRAT, and the MintsLoader for delivering further malware.
Microsoft advises organizations to limit unnecessary command-line utilities, activate PowerShell script-block logging, apply application-control policies, and enable comprehensive Defender protections covering network, web, and cloud threats. End users are warned not to paste commands drawn from CAPTCHA pages or unexpected support messages into Run, Terminal, PowerShell, or the command prompt.