Microsoft Warns Hackers Are Using BNB Chain to Spread Malware

Thu, 6/08/2026 - 20:26
Microsoft has uncovered a new malware campaign that abuses the BNB Smart Chain to make malicious infrastructure more resilient.
Advertisement
Microsoft Warns Hackers Are Using BNB Chain to Spread Malware
Cover image via commons.wikimedia.org
Google

Microsoft has uncovered a new malware campaign centered around BNB Smart Chain to make malicious infrastructure harder to take down. 

Advertisement

According to Microsoft Threat Intelligence, attackers have compromised legitimate websites and injected malicious JavaScript that communicates with a smart contract deployed on the aforementioned blockchain. 

The campaign relies on a technique known as EtherHiding, which is linked to the notorious ClearFake malware operation.

HOT Stories
Microsoft Warns Hackers Are Using BNB Chain to Spread Malware XRP 2026 Futures Axed as BitMEX Shuts Down; Coinbase Launches Free US Stocks in UK; Bitcoin Strategy Raises $15 Billion via ChatGPT: Michael Saylor — Morning Crypto Report

The malware retrieves its next-stage payload from a smart contract via a BNB Smart Chain RPC gateway. 

Advertisement

The infrastructure is significantly more resistant to conventional takedown efforts because only the owner of the wallet that deployed the contract can modify or remove its contents. 

Victims are then shown a fake CAPTCHA that instructs them to open the Windows Run dialog, paste clipboard contents, and execute an attacker-controlled command.

Microsoft said the attackers employ extensive command obfuscation techniques while abusing legitimate Windows tools such as PowerShell, Command Prompt, Windows Terminal, mshta, rundll32, WMI, curl, WebDAV, and so on. 

Advertisement

card

Once executed, the malware can deliver a variety of payloads, including Lumma Stealer, XWorm, AsyncRAT, MintsLoader, and remote management tools. Successful infections can expose credentials and ultimately pave the way for human-operated ransomware attacks.

Microsoft urged users to never paste commands from CAPTCHAs, browser warnings, advertisements, emails, and so on. 

The company also recommended organizations enable Microsoft Defender's network, web, and cloud protections, restrict unnecessary command-line utilities, and enable PowerShell logging. 

Other recent incidents 

Earlier this year, Microsoft issued multiple cryptocurrency-related security alerts. 

In June, Microsoft disclosed a cryptocurrency clipper campaign that stole clipboard contents and replaced copied wallet addresses with the ones that are controlled by the attacker. 

A month earlier, the company revealed a large-scale cryptojacking operation that combined SEO poisoning.

Microsoft has also repeatedly warned about ClickFix-style social engineering attacks. In May, researchers reported an infostealer campaign targeting macOS users through fake troubleshooting guides. 

Advertisement
Advertisement
Advertisement
Advertisement
Subscribe to daily newsletter

Recommended articles

Our social media
There's a lot to see there, too
Advertisement