Hackers Abuse BNB Chain to Spread Malware Through Fake CAPTCHAs
Hackers have been using BNB Chain contracts to spread malware through compromised websites and fake CAPTCHA prompts, according to a report by Microsoft Threat Intelligence.
The campaign uses EtherHiding, a technique that stores malicious instructions in a blockchain smart contract. JavaScript injected into compromised websites contacts a BNB Chain gateway and retrieves commands from a contract previously linked to ClearFake, a malware campaign that infects legitimate websites.
This method, known as ClickFix, depends on victims executing the malware themselves. A variation called TerminalFix directs users to Windows Terminal or PowerShell.
A successful infection can expose passwords, establish lasting access, and help hackers move through a network, ultimately leading to ransomware or broader network compromise.