The Latest Crypto News
Friday, 25 September 2026 BTC -- / --
🔍

Microsoft: BNB Smart Chain Abused to Spread Malware

BNB coin logo with a red malware warning shield.
BNB coin logo with a red malware warning shield.

Microsoft Threat Intelligence has discovered that attackers are using compromised websites to retrieve malicious commands via smart contracts on the BNB Smart Chain. The technique is known as EtherHiding and affects thousands of devices worldwide every day.

In brief:

  • Attackers abuse BNB Smart Chain contracts to send malware instructions via an RPC gateway.
  • Victims are lured through fake CAPTCHA pop-ups that prompt them to execute malicious commands themselves.
  • The campaigns, dubbed ClickFix and TerminalFix, target both business and private users worldwide.

Fake CAPTCHA as an entry point

The attack begins with a pop-up window that looks like a standard CAPTCHA verification. Users are instructed to press a key combination, namely the Windows key plus R, followed by Ctrl+V and Enter. What they do not know is that this pastes a malicious command and executes it directly on their system. The approach is deliberately kept simple so that even less technically savvy people fall for it.

The fake CAPTCHA method is part of the so-called ClickFix and TerminalFix campaigns. According to Microsoft, thousands of devices are affected daily through this attack route, both at large companies and among ordinary consumers at home.

EtherHiding via the blockchain

What technically sets this campaign apart is the use of the EtherHiding technique. Attackers store malicious instructions in smart contracts on the BNB Smart Chain. Compromised websites retrieve these instructions via a BNB Smart Chain RPC gateway, after which they are passed on to the victim’s device. Because the instructions are distributed via the blockchain, they are harder to block or remove than traditional malware infrastructure.

The network behind BNB is thus unwittingly deployed as an intermediary in an attack chain. Microsoft has published its findings and warns users and organisations to be alert to suspicious verification screens that ask them to perform keyboard actions.

Risk to enterprise and consumer

The scale of the campaign is remarkably large. Microsoft reports that the attacks are not limited to a single sector or target audience. Both office environments and home users are targeted. That makes the campaign more dangerous than targeted attacks, because the chance of a hit automatically increases with broad distribution.

Security experts recommend actively informing employees about this attack method. Legitimate CAPTCHA services never ask users to manually execute commands via the keyboard. Anyone who encounters such a screen would be wise to close the page immediately.

Summarize this article with AI

Not financial advice. The Latest Crypto News provides educational and informational content only. Crypto-assets are highly volatile and you can lose your entire investment. Always do your own research. Read our full disclaimer.

Affiliate disclosure. Some links on this site are affiliate links. If you sign up with a partner through one of them, we may earn a commission at no extra cost to you. This never influences our reporting. See our editorial guidelines.

More Scam News

More news ›