Thousands of websites infected with malware exploiting blockchain technology

A vast hacking campaign has recently been revealed, compromising thousands of websites to spread malware via blockchain technology. Researchers from the security platform Netskope have identified that more than 5,400 sites, primarily based on WordPress and PrestaShop, have been infiltrated to disseminate malicious payloads. This phenomenon marks a worrying evolution in the techniques used by cybercriminals, who are now exploiting smart contracts to make their attacks more flexible and difficult to neutralize.

According to alarming findings from the researchers, the hacking campaign has affected small businesses worldwide. Although the initial compromise method remains unknown, each affected site has experienced the insertion of a malicious script capable of retrieving payloads from a smart contract on a blockchain. This innovative method allows attackers to manage and adapt their attacks directly by modifying the code hosted on the blockchain.

The EtherHiding and ClickFix Methodology

The method used by the attackers, called EtherHiding, relies on a very precise infection scheme. Once the script is injected into the compromised site, it displays a fake CAPTCHA window, encouraging users to open a “Run” dialog on their Windows systems. They are prompted to paste a PowerShell command, leading to the download and execution of the malicious payload on the victim’s device. This tactic demonstrates how cybercriminals have refined their approach to deceive potentially vulnerable users.

Storing Malware in Smart Contracts

One of the main advantages of this approach for hackers is the ability to continuously modify the payload hosted in the smart contract. This allows them to change the nature of the attacks across all infected sites, effectively providing them with a malware infrastructure that is nearly permanent. By storing malicious code directly on a blockchain, the attackers create a rendezvous point that neither the hosting provider nor the domain registrar can easily remove. In this case, the cybercriminals have selected the BSC Testnet, the test network of the BNB Smart Chain, to carry out their operations, drawn by its free usage.

A Recent and Worrying Evolution of Threats

Netskope experts have also observed an evolution in the method of malware transmission. In a more recent variant, the payload that was initially loaded via ClickFix has been replaced by a WebRTC data channel. This new method offers encrypted communication between the attacker and the command and control server, allowing for the dynamic execution of code without leaving usual network artifacts. This means that the malicious code can be assembled directly in the browser’s memory and executed on the fly, making detection even more difficult.

For more details on threats related to cyberattacks using blockchain technology, you can check the following articles: securing your system against a North Korean cyberattack and discover the TrickMo banking malware hiding behind blockchain.

Scroll to Top