Altcoinbuzz Cybercriminals Exploit BNB Chain for Malware via Fake CAPTCHAs
Article Content
- •Cybercriminals are using EtherHiding on the BNB Smart Chain to deliver malware.
- •Victims are tricked into executing malicious commands via fake CAPTCHA prompts.
- •The ClickFix campaign is linked to the broader ClearFake malware operation.
Microsoft Threat Intelligence has reported a new malware campaign utilizing the BNB Smart Chain, employing a technique called EtherHiding. This method allows hackers to store malicious code within blockchain smart contracts, making it difficult for security teams to detect and remove. Victims are tricked into executing commands through fake CAPTCHA prompts on compromised websites. The malware primarily targets Windows systems, deploying information-stealing payloads like Lumma Stealer. The ClickFix campaign, linked to the ongoing ClearFake operation, has been confirmed to affect thousands of users daily. Microsoft advises users to avoid executing commands from CAPTCHA prompts and recommends organizations implement strict command-line controls. The campaign demonstrates the evolving tactics of cybercriminals leveraging blockchain technology to enhance malware delivery. This incident highlights the challenges of combating malware that utilizes decentralized infrastructure.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (12)
Following this threat?
Track Cerber, DPRK and ClearFake in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
North Korean Hackers Target Rust Developers with Job Scam North Korean threat actors are conducting a social engineering campaign targeting Rust developers and crate maintainers. The attackers lure victims into video calls under the pretense of job offers, tricking them into installing malware or executing malicious commands. The Rust Project's crates.io team issued a…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…