Hackers Use BNB Chain to Spread Malware Through Fake CAPTCHAs

Microsoft said compromised websites are using BNB Chain to retrieve malicious instructions before tricking visitors into running them on Windows devices. The campaign shows how public blockchains can be abused as part of malware delivery, even when the target is a conventional web user.

Hackers Use BNB Chain to Spread Malware Through Fake CAPTCHAs

What happened?

Microsoft said compromised websites are using BNB Chain to retrieve malicious instructions before tricking visitors into running them on Windows devices. The campaign shows how public blockchains can be abused as part of malware delivery, even when the target is a conventional web user.

Why it matters

Microsoft said hackers are using BNB Chain as part of a malware campaign that starts on compromised websites and ends with visitors being pushed to run malicious commands on Windows devices. According to the company, the sites retrieve instructions from the blockchain before presenting users with fake CAPTCHA prompts.

Microsoft said hackers are using BNB Chain as part of a malware campaign that starts on compromised websites and ends with visitors being pushed to run malicious commands on Windows devices. According to the company, the sites retrieve instructions from the blockchain before presenting users with fake CAPTCHA prompts.

The development matters because it shows attackers using crypto infrastructure as a distribution layer, not just as a target. For readers, the risk is practical: a familiar web security step, such as a CAPTCHA, can be imitated to make a malicious action look routine.

Microsoft’s finding points to a tactic in which compromised websites act as the first point of contact, while blockchain-based data helps deliver the next step in the attack. The source material does not indicate that BNB Chain itself was compromised.

The campaign also underscores a broader security issue for the crypto ecosystem: public blockchains can be used by anyone, including threat actors, to store or reference information. That openness is a core feature of blockchain networks, but it can also make abuse harder to remove once malicious instructions are posted.

Users should treat unexpected CAPTCHA pages that ask them to copy, paste, or run commands with caution, especially on Windows devices. The key warning from Microsoft’s report is that the attack depends on convincing the visitor to execute the instructions themselves.

Source: Decrypt

Keep exploring

Related stories

Polymarket Changes Crypto Market Rules After Manipulation Study

Polymarket Changes Crypto Market Rules After Manipulation Study

Polymarket is replacing instant settlement-price snapshots with time-weighted average prices for short-dated crypto markets. The change follows research and trader complaints that identified patterns consistent with settlement manipulation in five-minute bitcoin contracts.

Read
OKX Executive Questions Clarity Act Path as Bitcoin Optimism Faces Test

OKX Executive Questions Clarity Act Path as Bitcoin Optimism Faces Test

OKX executive Haider Rafique said he is skeptical that the Clarity Act will pass this year, citing political incentives in Congress. He also warned that much of the bill’s upside may already be reflected in bitcoin’s price.

Read
Bitcoin Reaches August High Above $65,000 After Soft US Jobs Data

Bitcoin Reaches August High Above $65,000 After Soft US Jobs Data

Bitcoin climbed above $65,000 to reach a month-to-date high as risk assets advanced following weaker US nonfarm payrolls data. The move came as traders reassessed expectations around Federal Reserve rate policy.

Read