Fun

News Feed - 2023-10-16 02:10:00

Martin Young3 hours agoEtherHiding: Hackers create novel way to hide malicious code in blockchainsThreat actors have worked out a way to hide malicious payloads in Binance smart contracts to lure victims into updating their browsers from fake prompts, according to cybersecurity researchers.2068 Total views19 Total sharesListen to article 0:00NewsJoin us on social networksCybercriminals have discovered a new way to spread malware to unsuspecting users, this time by manipulating BNB Smart Chain (BSC) smart contracts to hide malware and disseminate malicious code.


A breakdown of the technique known as “EtherHiding” was shared by security researchers at Guardio Labs in an Oct. 15 report, explaining that the attack involves compromising WordPress websites by injecting code that retrieves partial payloads from the blockchain contracts.


The attackers hide the payloads in BSC smart contracts, essentially serving as anonymous free hosting platforms for them.Guardio Labs exposes "EtherHiding" - a new threat hiding in Binance"s Smart Chain, a technique that evades detection, targeting compromised WordPress sites. Read about this game-changing method! @BNBCHAIN #BNBChain #CyberSecurity https://t.co/alNI5KqKUO— Guardio (@GuardioSecurity) October 15, 2023


The hackers can update the code and change the attack methods at will. The most recent attacks have come in the form of fake browser updates, where victims are prompted to update their browsers using a fake landing page and link.


The payload contains JavaScript that fetches additional code from the attacker’s domains. This eventually leads to full site defacement with fake browser update notices that distribute malware.


This approach allows the threat actors to modify the attack chain by simply swapping out malicious code with each new blockchain transaction. This makes it challenging to mitigate, according to Nati Tal, head of cybersecurity at Guardio Labs, and fellow security researcher Oleg Zaytsev.


Once the infected smart contracts are deployed, they operate autonomously. All Binance can do is rely on its developer community to flag malicious code in contracts upon discovery.Contract address flagged for scam activity. Source: Guard.io


Guardio stated that website owners using WordPress, which runs roughly 43% of all websites, need to be extra vigilant with their own security practices before adding:“WordPress sites are so vulnerable and frequently compromised, as they serve as primary gateways for these threats to reach a vast pool of victims.”


Related:Crypto investors under attack by new malware, reveals Cisco Talos


The firm concluded that Web3 and blockchain bring new possibilities for malicious campaigns to operate unchecked. “Adaptive defenses are needed to counter these emerging threats,” it said.


Collect this article as an NFTto preserve this moment in history and show your support for independent journalism in the crypto space.


Magazine:Blockchain detectives — Mt. Gox collapse saw birth of Chainalysis# Blockchain# Smart Contracts# Malware# Hackers# Scams# BSCAdd reactionAdd reactionRead moreHow to earn passive income with peer-to-peer lendingMeet the guerilla artist who staged a crypto ‘rug pull’ in front of the SECHow to build a DApp on Ethereum

News Feed

EasyA announces 1 million devs in ecosystem
Vince Quill1 hour agoEasyA announces 1 million devs in ecosystemThe Web3 educational platform also announced a Polkadot education initiative to help onboard new developers to the blockchain network.153 Total viewsListen
Vermont Rapper Releases Hip Hop Track ‘#Freeross,’ Ulbricht Petition Nears 300K Signatures
Vermont Rapper Releases Hip Hop Track "#Freeross," Ulbricht Petition Nears 300K Signatures Southern Vermont-based hip-hop artist, Krypto Man, has released a new single called &ld
Senate Banking Committee chair wants to combine stablecoin bill to boost chance of passage
Turner Wright2 hours agoSenate Banking Committee chair wants to combine stablecoin bill to boost chance of passageA bill in the House of Representatives aimed at providing guardrails for stablecoins has not moved forward
Google to Require Government Authorization to Provide Advertising Services for Financial Products in Spain
Google to Require Government Authorization to Provide Advertising Services for Financial Products in Spain Google, the web search and software monolith, has announced that it will
Dydx Processed $1.1 Billion Cryptocurrency Loans in 12 Months — 70% in Just 60 Days
Dydx Processed $1.1 Billion Cryptocurrency Loans in 12 Months — 70% in Just 60 Days Cryptocurrency lender Dydx advanced a total of $1.14 billion in digital asset loans over the pa
Federal Prosecutors Probe Democrats Over Donations From Sam Bankman-Fried
Federal Prosecutors Probe Democrats Over Donations From Sam Bankman-Fried Several members of the U.S. Democratic Party and campaign committees are reportedly being probed by federa
New zero energy storage tech could lead to immortal blockchains
Tristan Greene3 hours agoNew zero energy storage tech could lead to immortal blockchainsToday’s tech allows us to preserve data for thousands of years with zero energy usage, tomorrow’s could ensure Satoshi’s visio
Brazilian Federal Police Launch Operation Colossus, 6 Cryptocurrency Exchanges Involved
Brazilian Federal Police Launch Operation Colossus, 6 Cryptocurrency Exchanges Involved The Brazilian Federal Police and the Brazilian tax authority have launched the final stage o
Crypto losses to deep fakes could reach $25B in 2024 — Bitget
Felix Ng59 minutes agoCrypto losses to deep fakes could reach $25B in 2024 — BitgetCriminals are using deep fakes more than ever, causing $79.1 billion in losses since 2022.291 Total views2 Total sharesListen to articl
Australia to List Bitcoin ETF After 4 Clearinghouse Participants Commit to Meet Stringent Margin Terms
Australia to List Bitcoin ETF After 4 Clearinghouse Participants Commit to Meet Stringent Margin Terms Australia is set to get its first bitcoin exchange-traded fund (ETF) after a
Russia Releases Bitzlato Co-Founder Anton Shkurenko After Questioning
Russia Releases Bitzlato Co-Founder Anton Shkurenko After Questioning Russian authorities have released the recently arrested co-founder of crypto exchange Bitzlato, said to have p
Middle East accounts for 7.5% of global crypto volume — Chainalysis
Vince Quill7 hours agoMiddle East accounts for 7.5% of global crypto volume — ChainalysisAccording to the World Bank, less than 50% of adults in the Middle East and North Africa region had access to adequate banking se