Microsoft Identifies Malware Threat Using BNB Chain Smart Contracts to Hide Attack Commands

Microsoft Threat Intelligence has identified a widespread malware campaign that stores and retrieves attack instructions via smart contracts on the BNB Chain. The operation affects thousands of Windows systems daily, spanning both corporate networks and individual users.

Researchers describe the approach as EtherHiding, in which malicious JavaScript embedded on compromised websites queries a blockchain contract to obtain the latest commands.

The contract in question has prior connections to the ClearFake campaign.

Attackers present victims with counterfeit CAPTCHA challenges. These prompts urge users to open the Windows Run dialog, paste pre-loaded clipboard content, and execute it.

Variants known as TerminalFix instead direct people to Windows Terminal or PowerShell.

Because the instructions reside on the blockchain and can be altered only by the contract’s controlling wallet, standard disruption tactics such as server seizures prove ineffective.

Once the pasted command runs, the malware abuses legitimate Windows components including PowerShell, cmd, mshta, rundll32, msiexec, and scheduled tasks.

Obfuscation methods further conceal activity: caret characters break up keywords, environment variables hide interpreters, and processes launch in minimized windows.

Observed payloads include the Lumma Stealer for credential theft, remote-access tools such as Xworm and AsyncRAT, and the MintsLoader for delivering further malware.

Successful infections enable password harvesting, long-term system access, lateral movement within networks, and eventual deployment of human-operated ransomware that can jeopardize entire domains.

Microsoft advises organizations to limit unnecessary command-line utilities, activate PowerShell script-block logging, apply application-control policies, and enable comprehensive Defender protections covering network, web, and cloud threats.

End users receive a clear caution: never paste commands drawn from CAPTCHA pages, browser alerts, emails, advertisements, or unexpected support messages into Run, Terminal, PowerShell, or the command prompt.

Microsoft Defender XDR offers multi-stage detection.

SmartScreen and Defender for Office 365 can intercept malicious domains and fraudulent CAPTCHA pages early.

Defender for Endpoint flags suspicious command patterns and unusual outbound traffic, while antivirus signatures target the ClickFix and TermFix families.

Security teams should treat related alerts as potential initial-compromise indicators and isolate affected machines promptly.

The use of blockchain infrastructure for malware command-and-control is not unprecedented.

Earlier examples include the Cerber ransomware relying on Bitcoin transactions, the Glupteba botnet employing the Bitcoin blockchain for backup servers, ClearFake’s adoption of EtherHiding on BNB Chain in 2023, and the more recent Omnistealer that leveraged multiple chains including BNB.

The current advisory follows a June 2026 Microsoft report on CryptoBandits, a clipper malware that monitored the clipboard for cryptocurrency addresses and swapped them with attacker-controlled ones.

Although the technique is not exclusive to BNB Chain, the disclosure coincides with the network’s announced technical roadmap.

Plans include a new layer-1 blockchain optimized for high-frequency trading, automated payments, and AI-related transactions, with a testnet targeted for late 2026 and mainnet expected in early 2027.

The findings highlight the broader difficulty of neutralizing threats that exploit immutable or owner-controlled blockchain storage, underscoring the need for layered defenses that focus on user behavior and endpoint monitoring rather than solely on infrastructure takedowns.



Sponsored Links by DQ Promote

 

 

0 0 votes
Article Rating
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Newest
Oldest Most Voted
 
0
Would love your thoughts, please comment.x
()
x
Send this to a friend