BNB News Today: How EtherHiding Uses BNB Blockchain for Malware BNB News today centers on a malware in its BNB Smart Chain (BSC). Microsoft Threat Intelligence flagged a fresh wave of attacks
BNB News Today: How EtherHiding Uses BNB Blockchain for Malware
BNB News today centers on a malware in its BNB Smart Chain (BSC). Microsoft Threat Intelligence flagged a fresh wave of attacks that hide malware instructions inside BSC contracts. Hackers now pull commands straight from the blockchain instead of a regular server, and the campaign hits thousands of devices every day.

Source: Wu Blockchain Official
This BNB News update highlights attention towards cryptocurrency blockchain malware, a topic often failed to notice in abundance of direct hacks and exploits.
How the EtherHiding Attack Works on the BNB Smart Chain Network
Microsoft Threat Intelligence calls this method EtherHiding. The attack chain runs in a few clear steps:
Attackers break into legitimate websites and slip in hidden code.
A visitor's browser quietly contacts a BNB Smart Chain RPC gateway, including public nodes such as bsc-testnet-rpc.publicnode.com.
The script makes an eth_call to a smart contract tied to an older operation called ClearFake.
The contract sends back the next set of malicious instructions to the victim's machine.

Source: Microsoft Threat Intelligence, @MsftSecIntel
Because blockchain records cannot be altered by anyone outside the deploying wallet, teams cannot simply take the contract down like a rogue server.
The update today explains why EtherHiding malware worries researchers. BSC malicious code built this way keeps working even after a site gets cleaned, since the payload sits on the chain itself.
Fake CAPTCHA Prompts Trick Windows Users Into Running Malicious Code
This BNB News breakdown shows the infection chain leans on tricking people, not just code. Visitors see a fake CAPTCHA box asking them to prove they are human. The prompt walks them through three quick steps:
Press Windows key plus R to open the Run box.
Press Ctrl plus V to paste a hidden command from the clipboard.
Press Enter, which runs the command right away.

A close cousin called TerminalFix uses the same fake CAPTCHA malware trick inside Windows Terminal or PowerShell instead of the Run box.
Once a victim hits Enter, the machine runs code through trusted tools like PowerShell and rundll32.
Every update on this campaign points to stolen passwords, hidden backdoors, and a path toward ransomware.
BNB Price Today: What the Market Shows Alongside This Malware News
The Binance token today trades at $593.14 as this $BNB News report goes live, up 1.09% over the past 24 hours. A few other numbers stand out today:
Market cap: $78.98 billion
24-hour volume: $1.32B, up 38.31%
Circulating and total supply: 133.16M $BNB
Treasury holdings: 686.07K $BNB

Source: CoinMarketCap Official
None of this malware news moves $BNB price today or the value of the coin directly, since the flaw sits in website security, not in the token itself.
What Microsoft Defender Recommends to Block These Malware Attacks
Microsoft Defender points to a short list of steps:
Never paste text from a CAPTCHA or browser error into the Run box, Terminal, or PowerShell.
Turn on Microsoft Defender's network, web, and cloud-delivered protection along with SmartScreen.
Limit or disable the Run dialog through Group Policy or Intune where it fits.
Switch on PowerShell script-block logging and use Attack Surface Reduction rules.
Treat unusual Run history or ClickFix alerts as a possible break-in and isolate the device.
Watch browser calls to BSC endpoints to catch smart contract malware early.
How This EtherHiding Case Compares to Other Blockchain Malware Attacks
EtherHiding is not the first time hackers have used a blockchain as a hiding spot, and this BNB News comparison shows the pattern:
ClearFake (2023): Guardio Labs first spotted this campaign using BSC Chain contracts to store malicious code, the same base this new wave builds on.
UNC5342 campaigns: Google's Threat Intelligence Group tied North Korean actors to EtherHiding on both the Binance Chain and Ethereum, aimed at crypto theft and backdoor access.
Traditional C2 servers: Older malware relied on domains or IP addresses that defenders could block or seize, unlike a smart contract that stays live once deployed.
Each case shares one trait, and this BNB News comparison makes it clear: attackers pick blockchains because nobody can switch them off the way a hosting company can pull a server.
BNB Chain News Today: What It Means for Binance Blockchain Trust
BNB Smart Chain plays no active role here beyond acting as a public data store. Nothing points to involvement from the blockchain team or Binance, and no official statement on this advisory had surfaced as of August 6 to 8, 2026.
Explorers such as BscScan and community tagging remain the main defense against this kind of BSC Chain malware.
Earlier $BNB Chain News coverage traced EtherHiding back to 2023, when Guardio Labs first documented it inside the ClearFake campaign. Expect more blockchain-based delivery systems ahead.
This BNB News story proves the underlying infrastructure is no longer something anyone can simply switch off, so training users and locking down endpoints matters more than ever.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Crypto markets carry significant risk. Always do your own research before making any investment decisions.