Microsoft Warns Hackers Are Exploiting BNB Chain to Distribute Malware

TL;DR:
- Injection into legitimate sites: Attackers compromise third-party websites to insert malicious JavaScript code that communicates with the blockchain.
- Resilience to takedowns: The malicious infrastructure uses smart contracts on BNB Smart Chain, making unilateral removal of content by third parties impossible.
- Coordinated social engineering: The scheme combines fake CAPTCHAs with the ClickFix trick to induce the victim to execute malicious commands in the system console.
Microsoft Threat Intelligence issued a report on a new campaign in which hackers exploit BNB Chain to store and distribute malicious code. According to researchers, cybercriminals compromise legitimate websites and inject JavaScript scripts that connect with smart contracts hosted on the BNB Smart Chain network.
Microsoft Threat Intelligence has identified a cluster of compromised websites displaying ClickFix lures and using EtherHiding, a technique associated with the ClearFake campaign.
An injected Base64-encoded JavaScript contacts a BNB Smart Chain RPC gateway to query a smartโฆ pic.twitter.com/FOivGuUxVV
โฆ Continue reading the full article at the original source below.


