Microsoft Discovers New Attack Using BNB Chain Smart Contracts to Hide Malware

iconKuCoinFlash
Share
AI summary iconSummary
On-chain news broke on August 7 as Microsoft revealed a new attack campaign using BNB Smart Chain RPC gateways to host malware within smart contracts. Attackers lure users through compromised websites, employing CAPTCHA and system tools like PowerShell to execute malicious commands. The malware—including Lumma Stealer and Xworm—is stored on-chain, making it difficult to remove. These attacks, named ClickFix and TerminalFix, affect thousands of devices daily. New token listings on the chain may face similar risks if security measures are not strengthened.

According to ME News, on August 7 (UTC+8), Microsoft’s Threat Intelligence Team reported that a batch of compromised websites have been leveraging ClickFix and TerminalFix to initiate attacks, combined with EtherHiding techniques to access smart contracts via BNB Smart Chain RPC gateways and retrieve subsequent malicious commands. Since the malicious content is stored on-chain within smart contracts, only the wallet owner who deployed the contract can modify it, making removal through traditional takedown or blocking methods extremely difficult. Microsoft noted that attackers forge CAPTCHA verification pages to trick users into opening the Windows “Run” dialog, Terminal, or PowerShell, where they are prompted to paste and execute malicious commands. The attack extensively employs system tools such as conhost, PowerShell, mshta, rundll32, curl, WMI, and WebDAV for obfuscation and “Living-off-the-Land” tactics. Microsoft stated that ClickFix and TerminalFix have become prevalent initial infection vectors, affecting thousands of enterprise and personal devices globally each day. Multiple threat groups are using them to distribute malware including Lumma Stealer, Xworm, AsyncRAT, and MintsLoader, potentially leading to credential theft, lateral movement, and ransomware attacks. Microsoft advises users never to paste or execute any commands in the Windows “Run” dialog, Terminal, PowerShell, or Command Prompt based on prompts from CAPTCHA, website errors, emails, or advertisements. (Source: BlockBeats)

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.