Microsoft: Hackers Hide Malicious Code in BNB Chain Smart Contracts, Thousands of Devices Hit

Microsoft: Hackers Hide Malicious Code in BNB Chain Smart Contracts, Thousands of Devices Hit

N
News Editor
2026-08-07 02:56:06
Microsoft's threat intelligence team has disclosed a new attack campaign that abuses BNB Chain smart contracts to hide malicious code. Compromised websites use ClickFix and TerminalFix lures, combined with EtherHiding, to retrieve next-stage instructions from contracts through BNB Smart Chain RPC gateways. Because the malicious payload lives on-chain and only the wallet that deployed the contract can modify it, traditional takedown or blocking methods are hard to apply. Attackers fake CAPTCHA pages and trick users into opening Windows Run, Terminal, or PowerShell, then pasting and executing commands. The campaign leans heavily on built-in system tools such as conhost, PowerShell, mshta, rundll32, curl, WMI, and WebDAV for obfuscation and living-off-the-land techniques. Microsoft says ClickFix and TerminalFix have become high-frequency initial access vectors, affecting thousands of business and personal devices daily. Multiple groups are using them to distribute Lumma Stealer, Xworm, AsyncRAT, and MintsLoader, which could lead to credential theft, lateral movement, and ransomware. Microsoft advises users never to paste or run commands in Windows Run, Terminal, PowerShell, or Command Prompt based on CAPTCHA prompts, webpage errors, emails, or ads.

Microsoft's threat intelligence team said in a post on Aug 7, 2026 that it had found a wave of compromised websites abusing BNB Chain smart contracts to hide malicious code.

The campaign combines ClickFix and TerminalFix lures with a technique called EtherHiding. Victims are led through BNB Smart Chain RPC gateways to on-chain smart contracts that return next-stage instructions. Because the malicious payload sits in a smart contract, only the wallet that deployed the contract can change it, making standard takedown or blocking efforts ineffective.

Fake CAPTCHA pages used to run commands

Attackers create fake CAPTCHA pages and trick users into opening Windows Run, Terminal, or PowerShell, where they paste and execute commands. The attack chain relies on Windows system utilities including conhost, PowerShell, mshta, rundll32, curl, WMI, and WebDAV to obfuscate activity and operate in a living-off-the-land style.

Thousands of devices affected daily

ClickFix and TerminalFix have become high-frequency initial access vectors, Microsoft said. They hit thousands of business and personal devices each day. Several attack groups are using them to deliver Lumma Stealer, Xworm, AsyncRAT, and MintsLoader, and the intrusions can lead to credential theft, lateral movement, and ransomware.

Microsoft's advice

Microsoft tells users not to paste or run commands in Windows Run, Terminal, PowerShell, or Command Prompt based on CAPTCHA pages, webpage errors, emails, or ads.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
560

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.