Skip to content
Microsoft Warns Hackers Are Hiding Malware Commands Inside BNB Chain Smart Contracts

Microsoft Warns Hackers Are Hiding Malware Commands Inside BNB Chain Smart Contracts

Finance.Biggo August 7, 2026

A sophisticated malware operation is using smart contracts on the BNB Chain to deliver attack instructions to thousands of compromised Windows devices worldwide every day, according to new research from Microsoft Threat Intelligence. The campaign combines fake CAPTCHA verification prompts with blockchain infrastructure, making the malicious commands exceptionally difficult for security teams to remove.

The technique, known as EtherHiding, stores attacker instructions inside a blockchain smart contract rather than on a traditional server. When a visitor lands on a compromised website, injected JavaScript contacts a BNB Smart Chain RPC gateway and retrieves commands from a contract previously linked to the ClearFake malware campaign. Because only the wallet that deployed the contract can modify its contents, conventional takedown methods such as server seizures or sinkholing are ineffective.

"This campaign demonstrates that ClickFix and TerminalFix are a high-volume initial access technique," Microsoft researchers wrote in a post on X on Thursday. "Microsoft reports campaigns targeting thousands of enterprise and consumer devices globally every day, while some malvertising chains can funnel visitors to scam pages."

Victims encounter a fraudulent CAPTCHA page that instructs them to open the Windows Run dialog, paste text from their clipboard, and press Enter. The clipboard content has already been prepared by the attackers, and executing it immediately runs a malicious command on the target system. A variation called TerminalFix directs users to Windows Terminal or PowerShell instead, using the same social engineering approach.

Once the command is executed, attackers abuse a wide range of legitimate Windows utilities to carry out the infection. Microsoft observed the exploitation of PowerShell, cmd, conhost, mshta, rundll32, msiexec, curl, Windows Management Instrumentation, WebDAV protocols, and scheduled tasks. The attackers also employ multiple obfuscation techniques to hide their activity, including inserting caret characters to fragment recognizable keywords, manipulating environment variables to conceal interpreters, and launching Windows processes in minimized or invisible modes.

Note: Payloads identified by Microsoft Threat Intelligence as distributed through ClickFix and TerminalFix campaigns.

A successful infection can expose passwords, establish lasting access on compromised systems, and enable attackers to move laterally across corporate networks. Microsoft warned that this access ultimately creates a path for human-operated ransomware attacks and possible full domain compromise.

The use of blockchain technology to support malware operations is not new. In 2016, the Cerber ransomware began using Bitcoin transactions to locate its command-and-control servers. Between 2019 and 2021, the Glupteba botnet used the Bitcoin blockchain to find backup servers when its primary infrastructure went offline. In September 2023, ClearFake began using EtherHiding to retrieve malicious code from BNB Chain smart contracts. More recently, in April 2026, researchers discovered a malware strain called Omnistealer using the TRON, Aptos, and BNB Chain blockchains to steal credentials, cloud account information, passwords, and crypto wallet data.

Microsoft recommended several defensive measures for organizations. These include restricting access to unnecessary command-line tools, enabling PowerShell script-block logging, enforcing application control policies, and activating network, web, and cloud-delivered protection through Microsoft Defender. The company also issued a direct warning to end users.

"Users should never paste commands from CAPTCHAs, browser errors, emails, ads, or unsolicited support pages into Run, Terminal, PowerShell, or Command prompt," Microsoft said.

Microsoft Defender XDR provides layered detection across multiple stages of the attack chain. Defender SmartScreen and Defender for Office 365 can block access to malicious domains, phishing URLs, harmful attachments, and fraudulent CAPTCHA pages before users interact with them. Defender for Endpoint identifies suspicious command execution patterns and anomalous outbound network traffic. Microsoft Defender Antivirus detects malicious command sequences under signatures including Trojan:Win32/ClickFix.* and Trojan:Win32/TermFix.*. Security operations teams should treat these alerts as potential indicators of initial compromise and quarantine affected devices for thorough investigation.

The advisory follows a separate Microsoft Threat Intelligence report from June 2026 detailing a Windows-based clipper campaign called CryptoBandits. That malware spread through malicious .lnk shortcut files, monitored the clipboard every 500 milliseconds for cryptocurrency wallet addresses, seed phrases, and private keys, and replaced copied addresses with attacker-controlled alternatives. It routed communications through the Tor network, created scheduled tasks for persistence, captured screenshots, and executed attacker-supplied code to provide backdoor access.

The latest findings come as BNB Chain pursues an ambitious technical roadmap. In July, the network unveiled plans for a new layer-1 blockchain designed for high-frequency trading, automated payments, and AI-driven transactions. A testnet is expected by the end of 2026, followed by a mainnet launch in early 2027. While the malware issue is not unique to BNB Chain, Microsoft's decision to highlight the ongoing campaign underscores the growing challenge of blockchain-enabled cyber threats that resist traditional takedown methods.

Once added, BigGo Finance appears first in Google Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.