Altcoinbuzz
Microsoft Alerts on Malware Spread via BNB Chain Using Fake CAPTCHAs
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Microsoft has reported a new malware campaign exploiting the BNB Smart Chain to distribute malicious software through compromised websites. Attackers inject JavaScript that communicates with a smart contract on the BNB Chain, utilizing a technique known as EtherHiding, which makes the malicious infrastructure difficult to dismantle. Victims are tricked into executing commands via a fake CAPTCHA prompt, which instructs them to paste clipboard contents into the Windows Run dialog. This method leverages legitimate Windows tools to obfuscate commands and avoid detection. The malware can deploy various payloads, including credential stealers and remote access tools, potentially leading to human-operated ransomware attacks. Microsoft has advised organizations to restrict command-line tools and enhance logging to mitigate risks. This campaign is part of a broader trend of cybercriminals using blockchain technology for malware distribution.
Key Points: • Hackers exploit BNB Smart Chain to host malware, complicating takedown efforts. • Victims are tricked into executing malicious commands via fake CAPTCHA prompts. • Microsoft recommends restricting command-line tools and enhancing security logging.