XRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · GreedXRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · Greed
Home / Learn
● Learn

Hackers Weaponize BNB Chain Smart Contracts in Wide-Ranging Malware Campaign

Microsoft researchers identify active malware campaign using blockchain-based technique to distribute malicious code while evading traditional security takedowns.

JM
by Jacob Marquez · Learn Desk
Published August 7, 2026 · 3 min read

New Blockchain-Based Attack Method Emerges

Threat researchers at Microsoft have identified an active malware campaign leveraging BNB Chain smart contracts to distribute malicious code across compromised websites. The campaign, which builds on a technique known as EtherHiding, exemplifies how attackers are increasingly turning to blockchain infrastructure to make malware harder to detect and remove.

The attack begins when JavaScript code injected into compromised websites connects to a BNB Chain gateway and retrieves malicious instructions stored in a smart contract. This approach offers attackers a significant advantage: because only the wallet owner can modify the contract’s contents, traditional cybersecurity takedown efforts prove largely ineffective. The malware’s persistence on an immutable ledger makes detection substantially more difficult than conventional attack vectors.

The Social Engineering Component

Once users land on a compromised website, they encounter a convincing fake CAPTCHA prompt—a technique known as ClickFix. The fraudulent prompt instructs victims to open Windows’ Run dialog, paste clipboard text, and press Enter. A variation called TerminalFix redirects users to Windows Terminal or PowerShell instead. By tricking users into executing commands themselves, attackers bypass many security defenses that would block unauthorized program execution.

The malware leverages legitimate Windows tools including PowerShell, Command Prompt, mshta, rundll32, msiexec, curl, Windows Management Instrumentation, and scheduled tasks. A successful infection can expose user credentials, establish persistent access to compromised systems, enable lateral movement through corporate networks, and potentially lead to ransomware deployment or complete network compromise. According to Microsoft’s research, the campaign targets thousands of enterprise and consumer devices globally on a daily basis.

A Broader Pattern of Blockchain Abuse

This is not the first time threat actors have weaponized blockchain technology. The practice dates back to 2016 when Cerber ransomware used Bitcoin transactions to locate command-and-control servers. From 2019 through 2021, the Glupteba botnet exploited the Bitcoin blockchain to find backup infrastructure when primary servers went offline. More recently, the ClearFake malware campaign began employing EtherHiding on BNB Chain in September 2023. In April 2026, researchers documented Omnistealer using TRON, Aptos, and BNB Chain to harvest credentials, cloud account data, passwords, and cryptocurrency wallet information.

While this campaign specifically targets BNB Chain, the problem extends across multiple blockchain networks. The fact that Microsoft’s Threat Intelligence team chose to highlight this ongoing issue underscores the growing sophistication of attackers willing to abuse blockchain infrastructure for malicious purposes. As blockchain adoption expands, so too does its attractiveness to criminal elements seeking immutable command infrastructure. This serves as a cautionary reminder that blockchain networks, regardless of their intended purpose, can become tools for cybercriminals—a critical consideration for the wider crypto ecosystem.

Source: Microsoft Threat Intelligence, via Decrypt. Not financial advice.

// DISCLAIMER: This article is for informational purposes only and is not financial, investment, or trading advice. Terminalcraft may earn a commission from affiliate links. Crypto is volatile and high-risk. Always do your own research.
JM

Jacob Marquez — Learn Desk

Jacob Marquez is the founder and editor of Terminalcraft, an independent XRP-first crypto news desk. An XRP holder and market watcher since 2016, he started Terminalcraft to deliver fast, factual crypto news without the hype.