Fun

News Feed - 2023-10-16 02:10:00

Martin Young3 hours agoEtherHiding: Hackers create novel way to hide malicious code in blockchainsThreat actors have worked out a way to hide malicious payloads in Binance smart contracts to lure victims into updating their browsers from fake prompts, according to cybersecurity researchers.2068 Total views19 Total sharesListen to article 0:00NewsJoin us on social networksCybercriminals have discovered a new way to spread malware to unsuspecting users, this time by manipulating BNB Smart Chain (BSC) smart contracts to hide malware and disseminate malicious code.


A breakdown of the technique known as “EtherHiding” was shared by security researchers at Guardio Labs in an Oct. 15 report, explaining that the attack involves compromising WordPress websites by injecting code that retrieves partial payloads from the blockchain contracts.


The attackers hide the payloads in BSC smart contracts, essentially serving as anonymous free hosting platforms for them.Guardio Labs exposes "EtherHiding" - a new threat hiding in Binance"s Smart Chain, a technique that evades detection, targeting compromised WordPress sites. Read about this game-changing method! @BNBCHAIN #BNBChain #CyberSecurity https://t.co/alNI5KqKUO— Guardio (@GuardioSecurity) October 15, 2023


The hackers can update the code and change the attack methods at will. The most recent attacks have come in the form of fake browser updates, where victims are prompted to update their browsers using a fake landing page and link.


The payload contains JavaScript that fetches additional code from the attacker’s domains. This eventually leads to full site defacement with fake browser update notices that distribute malware.


This approach allows the threat actors to modify the attack chain by simply swapping out malicious code with each new blockchain transaction. This makes it challenging to mitigate, according to Nati Tal, head of cybersecurity at Guardio Labs, and fellow security researcher Oleg Zaytsev.


Once the infected smart contracts are deployed, they operate autonomously. All Binance can do is rely on its developer community to flag malicious code in contracts upon discovery.Contract address flagged for scam activity. Source: Guard.io


Guardio stated that website owners using WordPress, which runs roughly 43% of all websites, need to be extra vigilant with their own security practices before adding:“WordPress sites are so vulnerable and frequently compromised, as they serve as primary gateways for these threats to reach a vast pool of victims.”


Related:Crypto investors under attack by new malware, reveals Cisco Talos


The firm concluded that Web3 and blockchain bring new possibilities for malicious campaigns to operate unchecked. “Adaptive defenses are needed to counter these emerging threats,” it said.


Collect this article as an NFTto preserve this moment in history and show your support for independent journalism in the crypto space.


Magazine:Blockchain detectives — Mt. Gox collapse saw birth of Chainalysis# Blockchain# Smart Contracts# Malware# Hackers# Scams# BSCAdd reactionAdd reactionRead moreHow to earn passive income with peer-to-peer lendingMeet the guerilla artist who staged a crypto ‘rug pull’ in front of the SECHow to build a DApp on Ethereum

News Feed

Kickoff Your DeFi Adventure With Yearnify Finance – Get Your Tokens on Pre-Sale
Kickoff Your DeFi Adventure With Yearnify Finance – Get Your Tokens on Pre-Sale Decentralized Finance is definitely in the mainstream of the crypto industry. S
Spellfire: NFT That You Can Actually Touch
Spellfire: NFT That You Can Actually Touch sponsored In recent months NFT or as it coded, non-fungible tokens became a hot topic that everyone is talking about. NFT is a valuable mo
Turner Wright5 hours agoSam Bankman-Fried’s brother planned to buy island and prep for apocalypse: court filingAccording to court documents, Gabriel Bankman-Fried wrote a memo to the FTX Foundation with a plan to build
Bitcoin sats the ‘most valuable digital canvas ever’ — Ordinals artist
Brayden Lindrea3 hours agoBitcoin sats the ‘most valuable digital canvas ever’ — Ordinals artistBitcoin artist “Nuro” recently inscribed his 3D neurogenerative artwork on a $2 million “epic sat” from the la
FTX Launches Cross-Platform NFT Marketplace
FTX Launches Cross-Platform NFT Marketplace FTX, a spot and cryptocurrency exchange, announced the launch of an NFT marketplace on its trading platform today. According to the info
Tom Blackstone11 hours agoOPNX launches ‘oUSD’ credit currency for crypto margin tradingThe new “credit currency” will allow users to rely on cryptocurrencies as collateral without needing to obtain loans from ot
Bitget Integrates with TradingView For Crypto Derivatives Trading
Bitget Integrates with TradingView For Crypto Derivatives Trading press release PRESS RELEASE.VICTORIA, Seychelles— Bitget, a leading crypto derivatives exchange and copy trading
Professor Steve Hanke Says US Economy Was Flat Over the Last Year, but Stresses ‘It’s Going to Hit South’
Professor Steve Hanke Says US Economy Was Flat Over the Last Year, but Stresses ‘It’s Going to Hit South’ Amid the chaotic economy, plagued with central bank tinkering, suppl
IRS, Janet Yellen Press Lawmakers to Push ‘Tax Compliance Agenda’ — Banks to Report Deposits, Withdrawals of $600
IRS, Janet Yellen Press Lawmakers to Push "Tax Compliance Agenda" — Banks to Report Deposits, Withdrawals of $600 On Wednesday, U.S. Internal Revenue Service (IRS) commissioner C
Bittrex Receives Wells Notice From SEC for Alleged Investor-Protection Law Violations
Bittrex Receives Wells Notice From SEC for Alleged Investor-Protection Law Violations According to a recent report, the cryptocurrency exchange Bittrex received a Wells notice from
OVER Map2Earn: Revolutionary 3D Mapping is Now Available
OVER Map2Earn: Revolutionary 3D Mapping is Now Available sponsored OVER has launched the Map2Earn Beta program: revolutionary 3D mapping is now available to everyone. It is an innov
Fact Checking Media Tries to Debunk Great Reset Theories, Articles Ignite Heated Discussions Over Reboot Agenda
Fact Checking Media Tries to Debunk Great Reset Theories, Articles Ignite Heated Discussions Over Reboot Agenda On December 22, Twitter trends indicate that thousands of people on