BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Guides

Microsoft warns of BNB Smart Chain malware targeting Windows users

Microsoft has identified an ongoing malware campaign that utilizes BNB Smart Chain as an integral part of its infrastructure, making it more resistant to traditional takedown methods. Malware

AnonymousCryptoCompass newsroom
August 6, 2026
3 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for guides coverage.

Microsoft has identified an ongoing malware campaign that utilizes BNB Smart Chain as an integral part of its infrastructure, making it more resistant to traditional takedown methods.

Malware leverages blockchain smart contracts

Microsoft Threat Intelligence reported that cybercriminals have compromised legitimate websites, injecting them with malicious JavaScript code. This code communicates with a smart contract deployed on BNB Smart Chain, a blockchain network designed for decentralized applications and digital asset transactions.

The attack incorporates a method called EtherHiding, previously associated with the ClearFake malware operation known for its use of blockchain technology to evade detection and prevent intervention.

To persist within targeted environments, the malware retrieves additional malicious components from the smart contract through a BNB Smart Chain RPC (Remote Procedure Call) gateway.

Mini dictionary: EtherHiding, a technique that leverages blockchain smart contracts to dynamically deliver and update malicious content, allowing attackers to swap or remove malware instructions after deployment without needing direct access to the compromised web server.

Due to the structure of BNB Smart Chain, only the wallet owner who initiated the smart contract can change or remove its content. This configuration significantly complicates standard countermeasures such as infrastructure takedowns.

Attack vectors and techniques

When visiting a compromised website, victims are shown a counterfeit CAPTCHA prompt. The prompt instructs users to open the Windows Run dialog, paste content from their clipboard, and execute a command. This command is controlled by the attacker and initiates the malware infection process.

Cybercriminals use heavy command obfuscation and exploit built-in Windows utilities such as PowerShell, Command Prompt, Windows Terminal, mshta, rundll32, WMI, curl, and WebDAV to evade security measures and remain undetected.

Execution of the malicious command can lead to the download and installation of various malware payloads, including Lumma Stealer, XWorm, AsyncRAT, MintsLoader, and remote access tools that facilitate further compromise.

Successful infections may expose sensitive credentials and pave the way for more advanced attacks, including ransomware operations controlled by human attackers.

Microsoft’s recommendations

Microsoft advises users to avoid copying and executing commands from suspicious CAPTCHAs, pop-ups, browser warnings, advertisements, or emails. The company further recommends activating Microsoft Defender’s network, web, and cloud security features, restricting unnecessary command-line utilities, and enabling thorough PowerShell logging to improve detection and response.

For organizations, these steps are intended to reduce exposure to sophisticated attacks that abuse blockchain infrastructure for increased resilience.

Recent crypto-focused attacks

Earlier in the year, Microsoft highlighted a separate campaign involving a cryptocurrency clipper—a type of malware that intercepts clipboard data to substitute victims’ wallet addresses with those owned by attackers. This resulted in funds being diverted during cryptocurrency transactions.

In May, Microsoft sounded the alarm over large cryptojacking operations employing SEO poisoning to lure potential victims. Researchers also identified an infostealer campaign targeting macOS users through deceptive troubleshooting guides. ClickFix-style social engineering attacks remain a persistent threat, with attackers continuously adapting their tactics.

The post Microsoft warns of BNB Smart Chain malware targeting Windows users appeared first on COINTURK NEWS.