BNB Chain Used in Resilient Malware Campaign
Microsoft has detected a new malware campaign using BNB Chain to create resilient malicious infrastructure. The attackers have compromised legitimate websites, injecting malicious JavaScript that communicates with a smart contract deployed on the blockchain.
The campaign relies on the EtherHiding technique, linked to the notorious ClearFake malware operation. This allows the malware to retrieve its next-stage payload from a smart contract via a BNB Smart Chain RPC gateway.
Once executed, the malware can deliver various payloads, including Lumma Stealer, XWorm, AsyncRAT, MintsLoader, and remote management tools. Successful infections can expose credentials, paving the way for human-operated ransomware attacks.