Microsoft's threat intelligence team has revealed a campaign in which attackers store malicious commands inside BNB Smart Chain contracts and use them to push malware onto compromised websites. The distribution method relies on EtherHiding. Hackers query BSC's RPC gateway to pull the attack code from the chain, according to the disclosure. Microsoft said the approach exploits the immutability of blockchain to avoid detection. When a hacked website loads, it fetches and executes the malicious instructions held by the smart contract. The security team recommends tighter monitoring for site operators, warning specifically about the new trend of obtaining malicious code through blockchain nodes. The disclosure was carried by Techub News, citing Wu Blockchain.
Microsoft's threat intelligence team has found attackers using BNB Smart Chain contracts to host malicious commands. They distribute malware to compromised websites through EtherHiding, fetching the attack code from on-chain contracts via BSC's RPC gateway.
Microsoft says the method exploits the tamper-proof nature of blockchain to slip past detection. A compromised website loads and executes the malicious instructions stored in a smart contract. It advises website operators to strengthen monitoring against the emerging attack style, in which malicious code is fetched through blockchain nodes. (Wu Blockchain)
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.