Microsoft Issues BNB Smart Chain Alert: Method Targeting Thousands of Devices Daily Exposed
Microsoft has announced that cyber attackers are using smart contracts on the BNB Smart Chain (BSC) to spread malware instructions, targeting thousands of devices every day.
Tech giant Microsoft has warned users about a new cyberattack method exploiting the infrastructure of the cryptocurrency world. Investigations by the Microsoft Threat Intelligence team revealed that attackers are hiding malware instructions by using smart contracts on the BNB Smart Chain (BSC) network as data repositories. This method, named EtherHiding, aims to infiltrate users’ devices through compromised websites.
This complex attack chain begins with a fake CAPTCHA—an “I am not a robot” verification screen—presented to users. As seen in the images, attackers have designed a highly convincing interface to deceive users. Users are prompted to press the “Windows + R” keys on their keyboards, paste the copied malicious code using “Ctrl + V,” and then execute it. These simple steps actually result in the attackers’ commands being executed directly within the operating system.
Cyber Threats Executed via BNB Smart Chain
Researchers state that large-scale campaigns known as ClickFix and TerminalFix are behind this operation. Attackers access smart contracts by using the BSC network’s gateways—the Remote Procedure Call (RPC) nodes that communicate with the blockchain—to retrieve data. Consequently, traditional security software struggles to detect the source of the malicious code, as the data originates from a trusted blockchain network.
According to data shared by Microsoft, thousands of corporate and individual devices worldwide are targeted daily through this method. The decentralized structure of blockchain technology is, unfortunately, being used by malicious actors as a tool to make cyberattacks more persistent and stealthy. Users must be extremely cautious, particularly regarding verification screens that request unusual keyboard commands.