Hackers Hide Malware in BNB Chain Smart Contracts to Dodge Takedowns

3 min read
Hackers Hide Malware in BNB Chain Smart Contracts to Dodge Takedowns
PrimeXBT Editorial Team
Reviewed by PrimeXBT

Topics in article

BNB

Microsoft Threat Intelligence says hackers are storing malicious commands inside BNB Smart Chain contracts and delivering them through fake CAPTCHA prompts on hijacked websites. The technique, called EtherHiding, makes the payload nearly impossible to take down because only the wallet controlling the contract can change it, and the primary malware observed is the credential-stealing Lumma Stealer.

Hackers are hiding malware instructions inside BNB Chain smart contracts and spreading them through fake CAPTCHA prompts on compromised websites, Microsoft Threat Intelligence said in a post on X on Thursday. The technique, known as EtherHiding, stores malicious code directly on the blockchain rather than on servers security teams can seize.

How the fake CAPTCHA attack works

Typically on a hijacked WordPress site, injected JavaScript calls a BNB Chain gateway and pulls commands from a contract previously linked to the ClearFake malware campaign. The contract returns Base64-encoded instructions that the browser decodes and executes.

Visitors then see a fake CAPTCHA telling them to open the Windows Run dialog, paste text from their clipboard, and press Enter. Doing so runs a command the attacker supplied. The method, called ClickFix, depends on victims executing the malware themselves; a variation called TerminalFix instead directs them to Windows Terminal or PowerShell.

Only the wallet controlling the contract can change its contents, which limits the effectiveness of conventional takedowns. Attackers can also update it at any time by deploying new contracts, so the compromised site never needs to be touched again.

Lumma Stealer is the main payload

The campaign's primary payload is Lumma Stealer, an information stealer that harvests browser-stored passwords, cryptocurrency wallet credentials, and session cookies. Microsoft said hackers also abuse legitimate Windows tools, including PowerShell, cmd, mshta, rundll32, msiexec, curl, Windows Management Instrumentation, and scheduled tasks. According to Microsoft researchers: "This campaign demonstrates that ClickFix and TerminalFix are a high-volume initial access technique."

A successful infection can expose passwords, grant lasting access, and lead to ransomware or broader network compromise. Blockchain-based malware delivery is not new: Cerber ransomware used Bitcoin transactions to locate command-and-control servers in 2016, and the Glupteba botnet used the Bitcoin blockchain to find backup servers from 2019 to 2021. ClearFake itself began using EtherHiding on BNB Chain in September 2023.

Microsoft advised organizations to restrict unnecessary command-line tools, enable PowerShell logging, and use application controls. It also warned users never to paste commands from a CAPTCHA, browser error, email, ad, or unsolicited support page into Run, Terminal, PowerShell, or Command Prompt.

Sources: Decrypt, Crypto Briefing

Trading involves risk.

Most traded markets

XAU / USD
-0.9% 4,127.61
BRENT
+1.35% 73.620
BTC / USD
+0.7% 63,151.2
EUR / USD
-0.12% 1.14269
USTEC
-0.91% 29,428.7
XAU / USD.24
-0.9% 4,127.61
View all markets

Author

PrimeXBT
Our Editorial Team consists of leading experts with a proven record in the fields of trading, cryptocurrencies, blockchain and finance. We thoroughly research the sources of information in order to provide readers with quality content that serves edu...
Read author’s articles
Alert Triangle Risk Disclaimer
Disclaimer: Some past publications may be outdated. We recommend following our news to stay up to date with the latest information. For any questions, feel free to contact our support team via the chat below.
The content provided here is for informational purposes only. It is not intended as personal investment advice and does not constitute a solicitation or invitation to engage in any financial transactions, investments, or related activities. Past performance is not a reliable indicator of future results.
The financial products offered by the Company are complex and come with a high risk of losing money rapidly due to leverage. These products may not be suitable for all investors. Before engaging, you should consider whether you understand how these leveraged products work and whether you can afford the high risk of losing your money.
The Company does not accept clients from the Restricted Jurisdictions as indicated in our website/ T&C. Some services or products may not be available in your jurisdiction.
The applicable legal entity and its respective products and services depend on the client’s country of residence and the entity with which the client has established a contractual relationship during registration.

Today in markets

Browse Crypto News

Register Now

Trading involves risk

Get started in minutes

Our clients love how fast and simple our sign-up is. It takes just a few minutes to get started!

Get Started Get Started
Get started in minutes

Need Help?

Risk Warning:
Trading in leveraged products carries a high level of risk and may not be suitable for all investors.