Fun

News Feed - 2023-10-16 02:10:00

Martin Young3 hours agoEtherHiding: Hackers create novel way to hide malicious code in blockchainsThreat actors have worked out a way to hide malicious payloads in Binance smart contracts to lure victims into updating their browsers from fake prompts, according to cybersecurity researchers.2068 Total views19 Total sharesListen to article 0:00NewsJoin us on social networksCybercriminals have discovered a new way to spread malware to unsuspecting users, this time by manipulating BNB Smart Chain (BSC) smart contracts to hide malware and disseminate malicious code.


A breakdown of the technique known as “EtherHiding” was shared by security researchers at Guardio Labs in an Oct. 15 report, explaining that the attack involves compromising WordPress websites by injecting code that retrieves partial payloads from the blockchain contracts.


The attackers hide the payloads in BSC smart contracts, essentially serving as anonymous free hosting platforms for them.Guardio Labs exposes "EtherHiding" - a new threat hiding in Binance"s Smart Chain, a technique that evades detection, targeting compromised WordPress sites. Read about this game-changing method! @BNBCHAIN #BNBChain #CyberSecurity https://t.co/alNI5KqKUO— Guardio (@GuardioSecurity) October 15, 2023


The hackers can update the code and change the attack methods at will. The most recent attacks have come in the form of fake browser updates, where victims are prompted to update their browsers using a fake landing page and link.


The payload contains JavaScript that fetches additional code from the attacker’s domains. This eventually leads to full site defacement with fake browser update notices that distribute malware.


This approach allows the threat actors to modify the attack chain by simply swapping out malicious code with each new blockchain transaction. This makes it challenging to mitigate, according to Nati Tal, head of cybersecurity at Guardio Labs, and fellow security researcher Oleg Zaytsev.


Once the infected smart contracts are deployed, they operate autonomously. All Binance can do is rely on its developer community to flag malicious code in contracts upon discovery.Contract address flagged for scam activity. Source: Guard.io


Guardio stated that website owners using WordPress, which runs roughly 43% of all websites, need to be extra vigilant with their own security practices before adding:“WordPress sites are so vulnerable and frequently compromised, as they serve as primary gateways for these threats to reach a vast pool of victims.”


Related:Crypto investors under attack by new malware, reveals Cisco Talos


The firm concluded that Web3 and blockchain bring new possibilities for malicious campaigns to operate unchecked. “Adaptive defenses are needed to counter these emerging threats,” it said.


Collect this article as an NFTto preserve this moment in history and show your support for independent journalism in the crypto space.


Magazine:Blockchain detectives — Mt. Gox collapse saw birth of Chainalysis# Blockchain# Smart Contracts# Malware# Hackers# Scams# BSCAdd reactionAdd reactionRead moreHow to earn passive income with peer-to-peer lendingMeet the guerilla artist who staged a crypto ‘rug pull’ in front of the SECHow to build a DApp on Ethereum

News Feed

Stacks Activating Nakamoto Upgrade In 8 Days, Will STX Break $2?
Este artículo también está disponible en español. Stacks Network, the Bitcoin layer-2, is one of the largest DeFi protocols on the world’s most secure platform. DeF
The Great Financial Reset: IMF Managing Director Calls for a ‘New Bretton Woods Moment’
The Great Financial Reset: IMF Managing Director Calls for a "New Bretton Woods Moment" As the global economy shudders from the disastrous effects of central pla
As Bitcoin’s Price Spikes Pods of BTC Whales Begin to Shrink in Size
As Bitcoin"s Price Spikes Pods of BTC Whales Begin to Shrink in Size Recent metrics from a variety of analytical web portals show that the quantity of bitcoin whales has been shrin
Bitcoin Price Could ‘Easily Double’ In A Short Time, Predicts Hedge Fund CEO
Este artículo también está disponible en español. In the latest episode of The Milk Road Show, Charles Edwards, founder of crypto hedge fund Capriole Investments, provide
Helen Partz14 hours agoDo Kwon extradition approved by Montenegro courtMontenegro’s minister of justice will make the final decision on Do Kwon’s extradition to either South Korea or the United States.1527 Total view
Crypto exchange BitForex halts withdrawals, stops responding to users
David Attlee13 hours agoCrypto exchange BitForex halts withdrawals, stops responding to usersA Hong Kong-based crypto exchange has suspended withdrawals for at least three days without warning.10493 Total views14 Total s
Unido EP: Enterprise-Grade Digital Asset Management, for Everyone
Unido EP: Enterprise-Grade Digital Asset Management, for Everyone press release PRESS RELEASE.Since the last product offering comparison with Fireblocks, Unido has now successfully
Global Regulators Consider Launching a Joint Body to Coordinate Crypto Rules
Global Regulators Consider Launching a Joint Body to Coordinate Crypto Rules Global market regulators are likely to launch a joint body within the next year to better coordinate cr
Zimbabwe’s Mobile Money on Life Support as Central Bank Tightens Screws: Restrictions to Affect P2P Bitcoin Trading
Zimbabwe’s Mobile Money on Life Support as Central Bank Tightens Screws: Restrictions to Affect P2P Bitcoin TradingZimbabwe’s Mobile Money Operators (MMO) say they will comp
Elon Musk, Jack Dorsey, Cathie Wood Will Discuss Bitcoin Live at ‘B Word’ Event
Elon Musk, Jack Dorsey, Cathie Wood Will Discuss Bitcoin Live at "B Word" Event Tesla CEO Elon Musk, Twitter CEO Jack Dorsey, and Ark Invest CEO Cathie Wood will
Amaka Nwaokocha11 hours agoSam Bankman-Fried’s testimony to challenge government claims, lawyer tells judgeThe testimony will challenge the government‘s claims, especially the counsel’s role in auto-deletion, north
Proof-of-Work Ban Removed From Europe’s Proposed Crypto Regulation
Proof-of-Work Ban Removed From Europe’s Proposed Crypto Regulation A text threatening to prohibit cryptocurrencies relying on energy-intensive proof-of-work mining has been delet