(Advertisement)

top ad mobile advertisement
news7d ago

Microsoft flags malware campaign hiding its playbook on BNB Chain

Microsoft Threat Intelligence has identified a malware campaign using EtherHiding to store attack instructions inside BNB Smart Chain smart contracts, combining ClickFix social engineering to deploy Lumma Stealer and RATs on thousands of devices daily.

Microsoft flags malware campaign hiding its playbook on BNB Chain

(Advertisement)

native ad1 mobile advertisement

BNB Smart Chain Used to Shield Attack Instructions from Takedowns

@MsftSecIntel has identified a cluster of compromised websites deploying a technique known as EtherHiding, which stores next-stage attack instructions inside smart contracts on the BNB Smart Chain. The approach allows malicious traffic to blend with legitimate Web3 activity and, because the blockchain is immutable and decentralized, offers increased resilience against takedown efforts. Because only the deploying wallet can modify the contract, conventional sinkholing is largely ineffective.

Microsoft observed a cluster of compromised websites leveraging EtherHiding and ClickFix techniques to install Lumma Stealer. Attackers deploy the technique alongside EtherHiding, using smart contracts on the BNB Smart Chain to serve next-stage payloads, delivering tools such as Lumma Stealer. The campaign represents a convergence of social engineering and blockchain infrastructure that makes attribution and disruption considerably harder for defenders.

Fake CAPTCHAs Funnel Victims Toward Credential Theft and Ransomware

The infection chain begins with a fake CAPTCHA presented on a compromised site. Fake CAPTCHA pages are commonly observed in the ClickFix ecosystem, with targets instructed to copy malicious commands into their system's Run utility under the pretense of passing a verification check. These commands often download and execute malware directly in memory, using Base64 encoding and stealthy delivery chains.

ClickFix delivers infostealers such as Lumma Stealer, as well as remote access trojans and ransomware, with a single campaign sometimes deploying multiple malware families simultaneously. Lumma Stealer is a malware-as-a-service offering capable of stealing data from browsers and applications including cryptocurrency wallets, and of installing additional malware. Microsoft identified 394,000 infected Windows hosts in a 90-day window ending May 2025, with the FBI estimating 10 million cumulative infections globally.

Microsoft warns users to never paste commands sourced from a CAPTCHA prompt, browser error message, or support page into the Windows Run dialog, Terminal, or PowerShell. Minimizing password storage in browsers, enforcing multi-factor authentication, and periodically reviewing saved logins in Chrome, Edge, and other browsers can all help limit the damage if an infostealer is executed on a workstation.

Sources:
Microsoft Security Blog: Lumma Stealer delivery techniques and capabilities
The Hacker News: Microsoft discloses ClickFix attack using EtherHiding on BNB Smart Chain
The Register: Microsoft spots ClickFix campaign spreading Lumma Stealer

Latest News

Read More...

Author

Crypto Rich profile photoCrypto Rich

Rich has been researching cryptocurrency and blockchain technology for eight years and has served as a senior analyst at BSCN since its founding in 2020. He focuses on fundamental analysis of early-stage crypto projects and tokens and has published in-depth research reports on over 200 emerging protocols. Rich also writes about broader technology and scientific trends and maintains active involvement in the crypto community through X/Twitter Spaces, and leading industry events.

Join our newsletter

Sign up for the very best tutorials and the latest Web3 news.

Subscribe Here!
BSCN

BSCN

BSCN RSS Feed

BSCN is your destination for all things crypto and blockchain. Discover the latest cryptocurrency news, market analysis, and research covering Bitcoin, Ethereum, altcoins, memecoins and everything in between.

Microsoft flags malware campaign hiding its playbook on BNB Chain | BSCN Breaking News