Microsoft Threat Intelligence says hackers are storing malicious commands inside BNB Smart Chain contracts and delivering them through fake CAPTCHA prompts on hijacked websites. The technique, called EtherHiding, makes the payload nearly impossible to take down because only the wallet controlling the contract can change it, and the primary malware observed is the credential-stealing Lumma Stealer.
Hackers are hiding malware instructions inside BNB Chain smart contracts and spreading them through fake CAPTCHA prompts on compromised websites, Microsoft Threat Intelligence said in a post on X on Thursday. The technique, known as EtherHiding, stores malicious code directly on the blockchain rather than on servers security teams can seize.
How the fake CAPTCHA attack works
Typically on a hijacked WordPress site, injected JavaScript calls a BNB Chain gateway and pulls commands from a contract previously linked to the ClearFake malware campaign. The contract returns Base64-encoded instructions that the browser decodes and executes.
Visitors then see a fake CAPTCHA telling them to open the Windows Run dialog, paste text from their clipboard, and press Enter. Doing so runs a command the attacker supplied. The method, called ClickFix, depends on victims executing the malware themselves; a variation called TerminalFix instead directs them to Windows Terminal or PowerShell.
Only the wallet controlling the contract can change its contents, which limits the effectiveness of conventional takedowns. Attackers can also update it at any time by deploying new contracts, so the compromised site never needs to be touched again.
Lumma Stealer is the main payload
The campaign's primary payload is Lumma Stealer, an information stealer that harvests browser-stored passwords, cryptocurrency wallet credentials, and session cookies. Microsoft said hackers also abuse legitimate Windows tools, including PowerShell, cmd, mshta, rundll32, msiexec, curl, Windows Management Instrumentation, and scheduled tasks. According to Microsoft researchers: "This campaign demonstrates that ClickFix and TerminalFix are a high-volume initial access technique."
A successful infection can expose passwords, grant lasting access, and lead to ransomware or broader network compromise. Blockchain-based malware delivery is not new: Cerber ransomware used Bitcoin transactions to locate command-and-control servers in 2016, and the Glupteba botnet used the Bitcoin blockchain to find backup servers from 2019 to 2021. ClearFake itself began using EtherHiding on BNB Chain in September 2023.
Microsoft advised organizations to restrict unnecessary command-line tools, enable PowerShell logging, and use application controls. It also warned users never to paste commands from a CAPTCHA, browser error, email, ad, or unsolicited support page into Run, Terminal, PowerShell, or Command Prompt.
Sources: Decrypt, Crypto Briefing
Trading involves risk.