News

Hackers Use BNB Chain and Fake CAPTCHAs to Spread Windows Malware

Microsoft says attackers are storing malicious instructions on BNB Smart Chain. Fake CAPTCHA pages then push Windows users to execute those commands. The campaign uses EtherHiding, ClickFix and TerminalFix techniques to support malware infections globally.

Written By : Yusuf Islam
Reviewed By : Manisha Sharma

Hackers are using BNB Smart Chain to store malicious instructions while fake CAPTCHA pages trick Windows users into executing malware. Microsoft Threat Intelligence linked the campaign to EtherHiding, which places attacker commands inside blockchain smart contracts.

Attackers first compromise legitimate websites and inject JavaScript into them. That code connects to BNB Chain infrastructure and retrieves instructions from a smart contract tied to the ClearFake malware campaign.  The blockchain does not infect devices by itself. Instead, attackers rely on social engineering to persuade visitors to execute the retrieved commands on their computers.

Fake CAPTCHA Pages Turn Visitors Into Malware Runners

Victims see what appears to be a normal CAPTCHA verification page after visiting a compromised website. The page then asks them to open Windows Run, paste clipboard content and press Enter. That action launches attacker-controlled instructions. Microsoft calls this technique ClickFix, while another version called TerminalFix directs victims to Windows Terminal or PowerShell.

Why would a routine CAPTCHA ever need access to Windows Run or PowerShell? Microsoft says legitimate CAPTCHA checks should never require users to paste commands into system tools. Attackers can also misuse built-in Windows utilities, including PowerShell, cmd, rundll32 and scheduled tasks. Successful infections can expose passwords, steal credentials and create persistent access.

BNB Chain Storage Makes Malicious Commands Harder to Remove

EtherHiding changes where attackers keep part of their malware infrastructure. Instead of depending only on conventional servers, they place malicious instructions inside blockchain smart contracts.

Security teams can often block or remove malicious websites and command servers. Blockchain data creates a tougher challenge because changing the relevant contract requires control of its associated wallet.

This resilience gives attackers a storage layer that remains widely accessible. Still, they need compromised websites and deceptive prompts to turn stored instructions into an infection. Microsoft said ClickFix and TerminalFix campaigns target thousands of consumer and enterprise devices globally each day. The resulting access can support deeper corporate network compromises.

Also Read: FBI Arrest in Steam Malware Scam, Hackers Steal $220,000 in Cryptocurrency

Campaign Builds on Earlier Blockchain Malware Techniques

Attackers have used blockchain infrastructure in earlier malicious operations. Previous campaigns have relied on Bitcoin transactions and networks, including TRON, Aptos, and BNB Chain.

The technique does not expose a flaw unique to the BNB Chain. Instead, attackers exploit public blockchain infrastructure because it offers persistence, accessibility, and resistance to centralized removal.

Once malware gains access, attackers can steal credentials, maintain persistence, and move deeper into corporate environments. Microsoft said such access could eventually support ransomware attacks or wider network compromises. For users, the warning remains direct. Legitimate CAPTCHA systems do not ask visitors to paste commands into Windows Run, Command Prompt, Terminal, or PowerShell.

Conclusion

Microsoft’s findings show attackers are combining persistent blockchain storage with fake CAPTCHA prompts to deliver Windows malware. The BNB Chain itself does not infect users, but malicious smart-contract data can resist removal. Users should reject any CAPTCHA that asks them to open system tools or paste commands.

Join our WhatsApp Channel to get the latest news, exclusives and videos on WhatsApp

Crypto News Today: Bitcoin Outflows, XRPL Adds Nearly 490,000 Accounts, Trezor Data Breach

South Korea Tightens Crypto Rules as Offshore Flows Persist

Bitwise Tokenization Push Meets Forward Industries’ Solana Risk

Best Decentralized Exchanges (DEXs) on Ethereum in 2026

How to Track XRP Ledger Transactions: A Complete Guide for 2026