Back Altcoinbuzz Microsoft warns hackers are using BNB Chain to spread malware
Microsoft has warned of a new cyberattack that uses the BNB Smart Chain to make malware harder to detect and remove.
According to Microsoft Threat Intelligence , hackers have compromised legitimate websites and injected malicious JavaScript code that communicates with a smart contract deployed on the BNB Smart Chain.
The blockchain-based setup makes the attack infrastructure much more difficult for security teams to shut down than traditional malware servers.
The campaign uses a technique called EtherHiding , which has previously been linked to the ClearFake malware operation.
Instead of storing malicious instructions on a normal web server, attackers keep them inside a blockchain smart contract. Because only the wallet owner can modify or remove the contract, security researchers cannot easily take it offline.
When users visit an infected website, they are shown a fake CAPTCHA verification page.
Rather than asking users to solve a simple challenge, the page instructs them to:
If the user follows these steps, the malware begins downloading and running on the device.
Microsoft says the attackers use several legitimate Windows utilities to avoid detection.
The attackers also heavily obfuscate their commands, making them much harder for traditional security software to recognize.
Once installed, the attack can deploy several well-known malware families, including:
These programs can steal passwords, browser data, cryptocurrency wallet information, and other sensitive files.
Microsoft warns that infected systems could eventually become targets for human-operated ransomware attacks , where attackers manually take control of compromised networks before encrypting files.
Microsoft strongly advises users never to copy and paste commands from:
Legitimate CAPTCHA systems never require users to run commands on their computers.
For businesses, Microsoft recommends enabling:
These measures can help detect and block similar attacks before they spread across an organization.
This is not the first cryptocurrency-related security warning Microsoft has issued this year.
In June , the company uncovered a clipboard hijacking campaign that replaced copied cryptocurrency wallet addresses with attacker-controlled addresses, allowing hackers to steal digital assets.
A month earlier, Microsoft also reported a large-scale cryptojacking campaign that used SEO poisoning to lure victims into installing malicious software.
The company has also repeatedly warned users ClickFix-style social engineering attacks , where fake troubleshooting pages trick people into running harmful commands. More recently, security researchers identified an information-stealing campaign targeting macOS users through fake technical support guides.
The latest campaign shows that cybercriminals are increasingly using blockchain technology to make malware more difficult to detect and remove.
While the BNB Smart Chain itself remains secure, attackers are abusing its decentralized infrastructure to host malicious code that cannot be easily taken offline.
Users should remain cautious when visiting unfamiliar websites and should never run commands requested by online CAPTCHA pages or browser pop-ups. Following basic security practices can help prevent malware infections and protect sensitive personal and financial information.
Bitcoin holders could lose real BTC if they sell coins from a BIP-110 fork before replay protection is active. Developers urge caution if the chain splits.
Coinfest Asia 2026 returns to Bali on August 20–21 with dedicated tracks for institutions, builders, and traders, connecting the global Web3 community.
Learn how businesses can avoid crypto payment scams through secure wallet management, compliance, verified payment systems and strong internal controls for safer digital asset transactions.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
