Hackers Hid Malware in BNB Smart Contracts and Told Users to Paste It Themselves 🤡
Hackers are using BNB Chain contracts to distribute malware through compromised websites and fake CAPTCHA prompts, according to Microsoft Threat Intelligence. In an X post on Thursday, the team described a campaign that leverages EtherHiding, a technique that stores malicious instructions in a blockchain smart contract. JavaScript injected into compromised sites contacts a BNB Chain gateway and pulls commands from a contract previously linked to ClearFake, a malware operation that infects legitimate websites. Storing instructions on a blockchain makes them harder to remove, since only the wallet controlling the contract can alter its contents, limiting the effectiveness of standard takedowns.
Visitors to compromised sites see a fake CAPTCHA instructing them to open the Windows Run dialog, paste text from their clipboard, and press Enter. Doing so executes an attacker-supplied command. The method, known as ClickFix, relies on victims running the malware themselves. A variant called TerminalFix directs users to Windows Terminal or PowerShell. "This campaign demonstrates that ClickFix and TerminalFix are a high-volume initial access technique," Microsoft researchers wrote. "Microsoft reports campaigns targeting thousands of enterprise and consumer devices globally every day, while some malvertising chains can funnel visitors to scam pages."
Microsoft said attackers hide their commands and abuse legitimate Windows tools, including PowerShell, cmd, mshta, rundll32, msiexec, curl, Windows Management Instrumentation, and scheduled tasks. A successful infection can expose passwords, establish lasting access, help attackers move laterally through a network, and lead to ransomware or broader compromise. The firm advised organizations to restrict unnecessary command-line tools, enable PowerShell logging, and use application controls, and warned that "users should never paste commands from CAPTCHAs, browser errors, emails, ads, or unsolicited" sources.
The use of blockchains to support malware is not new. In 2016, Cerber ransomware began using $BTC transactions to locate its command-and-control servers. From 2019 to 2021, the Glupteba botnet used the $BTC blockchain to find backup servers when its main ones went offline. In September 2023, ClearFake began using EtherHiding to retrieve malicious code from BNB Chain smart contracts, and in April 2026, researchers found Omnistealer using TRON, Aptos, and BNB Chain to help steal credentials, cloud account information, passwords, and crypto wallet data. The disclosure follows BNB Chain's July announcement of plans for a new layer-1 blockchain built for high-frequency trading, automated payments, and AI-driven transactions, with a testnet expected by the end of 2026 and a mainnet launch targeted for early 2027.
Mentioned Coins
Share Article
Quick Info
Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.
See our Terms of Service, Privacy Policy, and Editorial Policy.