Microsoft has detected a malware campaign using the BNB Smart Chain. Attackers are hijacking legitimate websites and embedding malicious JavaScript code into these pages. This code communicates with a smart contract deployed on the BNB Smart Chain. The attack is said to be based on the EtherHiding technique associated with the ClearFake operation. The malware loads from a smart contract via the BNB Smart Chain RPC gateway, and this structure appears to be more resilient against intervention methods. Users are shown a fake CAPTCHA screen, which prompts them to open the Windows Run dialog and execute commands from the attackers. Microsoft noted that the attackers used obfuscation techniques to hide their commands and exploited legitimate Windows tools. After the malicious code is executed, various payloads such as Lumma Stealer, XWorm, AsyncRAT, and MintsLoader can be downloaded. Successful infections can expose credentials and lead to human-controlled ransomware attacks. Microsoft advised organizations to enable network, web, and cloud protections, restrict unnecessary command-line tools, and enable PowerShell logging.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























