Microsoft Threat Intelligence has identified a new cyberattack method in which attackers are using smart contracts on the BNB Smart Chain to distribute malware instructions.
According to Microsoft, attackers are using a technique called “EtherHiding” on compromised websites. In this method, instead of receiving malicious instructions directly from a classic server controlled by the attackers, they are extracted from a smart contract on the BNB Smart Chain via an RPC gateway.
A key component of the attack chain is the use of fake CAPTCHA screens. These pages, designed to give users the impression of a genuine verification process, instruct them to press Windows + R, then paste a pre-placed command into the clipboard using Ctrl + V, and finally press Enter. In this way, the user unknowingly executes malicious commands prepared by the attackers on their own computer.
Microsoft stated that this method is particularly used in social engineering campaigns known as ClickFix and TerminalFix. According to the company, these campaigns target thousands of corporate and personal devices worldwide every day.
Using blockchain infrastructure as part of an attack chain allows attackers to update instructions through a distributed and publicly accessible infrastructure instead of a centralized server. This also represents a novel method that can make it more difficult to detect and completely disable malicious infrastructure.
*This is not investment advice.


