A malware campaign called ClickFix uses a technique called EtherHiding on the BNB Smart Chain to distribute the information-stealing malware Lumma Stealer via fake CAPTCHAs. Attackers target compromised WordPress sites and trick visitors into executing commands that install the malware on their Windows machines. Identified by Microsoft Threat Intelligence and linked to the ClearFake initiative, this campaign affects thousands of users daily, targeting both consumers and enterprises. The permissionless nature of the blockchain allows attackers to update their payloads by deploying new smart contracts without modifying compromised websites.
Source: Read the original article

