Hackers are using BNB Smart Chain contracts to spread malware through compromised websites and fake CAPTCHA prompts, according to Microsoft Threat Intelligence. The EtherHiding technique retrieves malicious commands from BNB Chain smart contracts, making them harder to remove as only the controlling wallet can modify the contents. Victims are tricked into pasting malicious commands into Windows tools like the Run dialog, PowerShell, or Command Prompt through ClickFix and TerminalFix methods. Successful infections can steal credentials, establish persistent access to corporate networks, enable lateral movement, and lead to ransomware attacks. Microsoft advises organizations to restrict unnecessary command-line tools, enable PowerShell logging, and use application controls, while warning users to never paste commands from CAPTCHAs or unsolicited pages.
Source: Read the original article

