AltcoinBuzzAltcoinBuzz
Subscribe
  • Crypto News
  • Crypto Research
  • Technical Analysis
AltcoinBuzzAltcoinBuzz

An independent digital media outlet delivering crypto research, news, and technical analysis to a community of 600,000+ users.

Follow us on:

Discover

  • Crypto Research
  • Crypto News
  • Technical Analysis
  • Key Opinions
  • Upcoming Launches

Categories

  • Bitcoin BTC
  • RWA
  • Technology
  • Altcoins
  • Regulation

Company

  • Affiliates
  • Partners & Sponsors
  • Careers
  • Contact
  • Terms of Use
  • Subscription Terms
  • About the ALTCOINBUZZ
  • Privacy Policy
  • Contact ALTCOINBUZZ
  • Advertise with us

Copyright 2026 ALTCOINBUZZ. All rights reserved.Something is buzzzzzzzing.
HomeCrypto ResearchMicrosoft warns hackers are using BNB Chain to spread malware
Crypto ResearchTechnology

Microsoft warns hackers are using BNB Chain to spread malware

Microsoft has uncovered a new malware campaign that uses BNB Smart Chain to hide malicious code. The attack tricks users into running fake CAPTCHA commands that can install password-stealing malware and remote access tools.

BBikash Deka•Aug 7, 2026
Microsoft warns that hackers are using BNB Smart Chain to distribute malware through fake CAPTCHA attacks.
MentionedBNB$592.58-0.20%

Microsoft has warned of a new cyberattack that uses the BNB Smart Chain to make malware harder to detect and remove.

According to Microsoft Threat Intelligence, hackers have compromised legitimate websites and injected malicious JavaScript code that communicates with a smart contract deployed on the BNB Smart Chain.

The blockchain-based setup makes the attack infrastructure much more difficult for security teams to shut down than traditional malware servers.

How the Attack Works

The campaign uses a technique called EtherHiding, which has previously been linked to the ClearFake malware operation.

Instead of storing malicious instructions on a normal web server, attackers keep them inside a blockchain smart contract. Because only the wallet owner can modify or remove the contract, security researchers cannot easily take it offline.

When users visit an infected website, they are shown a fake CAPTCHA verification page.

Rather than asking users to solve a simple challenge, the page instructs them to:

  • Open the Windows Run dialog.
  • Paste a command copied to the clipboard.
  • Execute the command on their computer.

If the user follows these steps, the malware begins downloading and running on the device.

Malware Uses Trusted Windows Tools

Microsoft says the attackers use several legitimate Windows utilities to avoid detection.

These include:

  • PowerShell
  • Command Prompt
  • Windows Terminal
  • mshta
  • rundll32
  • Windows Management Instrumentation (WMI)
  • curl
  • WebDAV

The attackers also heavily obfuscate their commands, making them much harder for traditional security software to recognize.

Multiple Malware Families Delivered

Once installed, the attack can deploy several well-known malware families, including:

  • Lumma Stealer
  • XWorm
  • AsyncRAT
  • MintsLoader
  • Remote management tools

These programs can steal passwords, browser data, cryptocurrency wallet information, and other sensitive files.

Microsoft warns that infected systems could eventually become targets for human-operated ransomware attacks, where attackers manually take control of compromised networks before encrypting files.

Microsoft Shares Security Advice

Microsoft strongly advises users never to copy and paste commands from:

  • CAPTCHA verification pages
  • Browser pop-ups
  • Online advertisements
  • Emails
  • Unknown websites

Legitimate CAPTCHA systems never require users to run commands on their computers.

For businesses, Microsoft recommends enabling:

  • Microsoft Defender network protection
  • Web protection
  • Cloud-based security features
  • PowerShell logging
  • Restrictions on unnecessary command-line tools

These measures can help detect and block similar attacks before they spread across an organization.

Microsoft Has Issued Similar Crypto Security Warnings Before

This is not the first cryptocurrency-related security warning Microsoft has issued this year.

In June, the company uncovered a clipboard hijacking campaign that replaced copied cryptocurrency wallet addresses with attacker-controlled addresses, allowing hackers to steal digital assets.

A month earlier, Microsoft also reported a large-scale cryptojacking campaign that used SEO poisoning to lure victims into installing malicious software.

The company has also repeatedly warned users about ClickFix-style social engineering attacks, where fake troubleshooting pages trick people into running harmful commands. More recently, security researchers identified an information-stealing campaign targeting macOS users through fake technical support guides.

What This Means

The latest campaign shows that cybercriminals are increasingly using blockchain technology to make malware more difficult to detect and remove.

While the BNB Smart Chain itself remains secure, attackers are abusing its decentralized infrastructure to host malicious code that cannot be easily taken offline.

Users should remain cautious when visiting unfamiliar websites and should never run commands requested by online CAPTCHA pages or browser pop-ups. Following basic security practices can help prevent malware infections and protect sensitive personal and financial information.

The information discussed by Altcoin Buzz is not financial advice. This is for educational, entertainment, and informational purposes only. Any information or strategies are thoughts and opinions relevant to the accepted levels of risk tolerance of the writer/reviewers and their risk tolerance may be different than yours. We are not responsible for any losses that you may incur as a result of any investments directly or indirectly related to the information provided. Bitcoin and other cryptocurrencies are high-risk investments so please do your due diligence. This post is sponsored by Market Across.

Copyright Altcoin Buzz Pte Ltd.

Related

Coinfest Asia 2026 brings together global Web3 leaders, crypto companies, builders, traders, and institutions in Bali, Indonesia.
Key Opinions
Aug 6, 2026

Coinfest Asia 2026 Connects Institutions, Builders and Traders to The World’s Crypto Festival

Coinfest Asia 2026 returns to Bali on August 20–21 with dedicated tracks for institutions, builders, and traders, connecting the global Web3 community.

Shash
avoid-scams
RegulationEduTech
Jul 21, 2026

How businesses can avoid crypto scams

Learn how businesses can avoid crypto payment scams through secure wallet management, compliance, verified payment systems and strong internal controls for safer digital asset transactions.

Saloni Rathi
XXKK-exchange
RegulationTechnology
Jul 21, 2026

XXKK Exchange: The Reasoning Behind its Multilateral Trading Method of Licensing, Security Structure and Infrastructure

An overview of XXKK Exchange covering its regulatory registrations, security features, trading products, fee structure, and risk considerations for cryptocurrency traders.

Saloni Rathi