Hackers Abuse BNB Chain to Spread Malware
Attackers are turning BNB Smart Chain into malware infrastructure, hiding the commands their malware fetches inside smart contracts, where they are far harder to take down than a normal server.
Microsoft's threat researchers describe the chain: a victim hits a fake CAPTCHA page that instructs them to paste and run a command in Windows, which installs the malware. From there it reads its next instructions and payloads straight from a BNB Smart Chain smart contract, a technique sometimes called EtherHiding. Because the data lives onchain, defenders cannot simply delete a file or block a server to shut it down.
It is a reminder that a public blockchain's censorship-resistance cuts both ways: the same permanence that protects legitimate apps also gives attackers durable, tamper-proof hosting.