Key facts
- Hackers are using BNB Smart Chain contracts to store malware instructions.
- Malware is delivered to victims via fake CAPTCHA prompts on compromised websites.
- The technique is known as EtherHiding.
- This method makes malicious commands difficult to remove.
- The attacks aim to steal credentials and compromise networks.
Hackers are utilizing BNB Smart Chain contracts as a novel method to store and distribute malware. This technique, referred to as EtherHiding, involves embedding malicious instructions within the smart contracts deployed on the blockchain. Victims encounter these malicious commands when they interact with compromised websites that display fake CAPTCHA prompts. When a user attempts to solve the CAPTCHA, they inadvertently trigger the execution of the hidden malware instructions. This approach makes it challenging to identify and remove the malicious code, as it is stored on the blockchain. The primary objectives of these attacks appear to be credential theft and broader network compromise. By successfully executing the malware, attackers can gain unauthorized access to sensitive information and potentially control victim systems.
