Fun

News Feed - 2023-10-16 02:10:00

Martin Young3 hours agoEtherHiding: Hackers create novel way to hide malicious code in blockchainsThreat actors have worked out a way to hide malicious payloads in Binance smart contracts to lure victims into updating their browsers from fake prompts, according to cybersecurity researchers.2068 Total views19 Total sharesListen to article 0:00NewsJoin us on social networksCybercriminals have discovered a new way to spread malware to unsuspecting users, this time by manipulating BNB Smart Chain (BSC) smart contracts to hide malware and disseminate malicious code.


A breakdown of the technique known as “EtherHiding” was shared by security researchers at Guardio Labs in an Oct. 15 report, explaining that the attack involves compromising WordPress websites by injecting code that retrieves partial payloads from the blockchain contracts.


The attackers hide the payloads in BSC smart contracts, essentially serving as anonymous free hosting platforms for them.Guardio Labs exposes "EtherHiding" - a new threat hiding in Binance"s Smart Chain, a technique that evades detection, targeting compromised WordPress sites. Read about this game-changing method! @BNBCHAIN #BNBChain #CyberSecurity https://t.co/alNI5KqKUO— Guardio (@GuardioSecurity) October 15, 2023


The hackers can update the code and change the attack methods at will. The most recent attacks have come in the form of fake browser updates, where victims are prompted to update their browsers using a fake landing page and link.


The payload contains JavaScript that fetches additional code from the attacker’s domains. This eventually leads to full site defacement with fake browser update notices that distribute malware.


This approach allows the threat actors to modify the attack chain by simply swapping out malicious code with each new blockchain transaction. This makes it challenging to mitigate, according to Nati Tal, head of cybersecurity at Guardio Labs, and fellow security researcher Oleg Zaytsev.


Once the infected smart contracts are deployed, they operate autonomously. All Binance can do is rely on its developer community to flag malicious code in contracts upon discovery.Contract address flagged for scam activity. Source: Guard.io


Guardio stated that website owners using WordPress, which runs roughly 43% of all websites, need to be extra vigilant with their own security practices before adding:“WordPress sites are so vulnerable and frequently compromised, as they serve as primary gateways for these threats to reach a vast pool of victims.”


Related:Crypto investors under attack by new malware, reveals Cisco Talos


The firm concluded that Web3 and blockchain bring new possibilities for malicious campaigns to operate unchecked. “Adaptive defenses are needed to counter these emerging threats,” it said.


Collect this article as an NFTto preserve this moment in history and show your support for independent journalism in the crypto space.


Magazine:Blockchain detectives — Mt. Gox collapse saw birth of Chainalysis# Blockchain# Smart Contracts# Malware# Hackers# Scams# BSCAdd reactionAdd reactionRead moreHow to earn passive income with peer-to-peer lendingMeet the guerilla artist who staged a crypto ‘rug pull’ in front of the SECHow to build a DApp on Ethereum

News Feed

IRS releases draft of 2025 digital asset reporting form for US taxpayers
Derek Andersen2 hours agoIRS releases draft of 2025 digital asset reporting form for US taxpayersThe U.S. Internal Revenue Service has been grappling with crypto tax reporting for years, and they may have a ways to go st
Arijit Sarkar14 hours agoCelsius valuation advisor approves value of debtors’ assets and liabilitiesStout Risius Ross, the valuation advisor for Celsius Network, confirmed the accuracy of the bankrupt firm’s valuatio
France’s Le Maire Attacks Facebook’s ‘Political’ Ambitions With Libra
France’s economic and finance minister says Libra is “unacceptable,” calling it an intrusion into the state’s political sovereignty. Writing in a Financi
Why reports of the death of NFTs are greatly exaggerated
Ezra Reguerra12 hours agoWhy reports of the death of NFTs are greatly exaggeratedToshiuki Otsuka, who founded a snap-to-earn platform, strongly opposed the narrative and argued that NFTs are "evolving."1151 Tot
Biggest Movers: LTC Climbs to Highest Level Since May
Biggest Movers: LTC Climbs to Highest Level Since May Litecoin rose to a seven-month high to start the week, as cryptocurrency markets continued to react to the latest U.S. nonfarm
Chainlink CCIP revenue surges 180% over 2 months amid ‘massive adoption’
Martin Young4 hours agoChainlink CCIP revenue surges 180% over 2 months amid ‘massive adoption’The cumulative revenue for the cross-chain protocol which launched in July 2023 has reached $377,724.2597 Total views3 To
$100 Million Liquidated on Defi Protocol Compound Following Oracle Exploit
$100 Million Liquidated on Defi Protocol Compound Following Oracle Exploit Lenders on decentralized finance (defi) protocol Compound on Thursday got liquidated f
Bitcoin, Ethereum Technical Analysis: BTC Rebounds, Moves Away From 1-Month Low
Bitcoin, Ethereum Technical Analysis: BTC Rebounds, Moves Away From 1-Month Low Market uncertainty in crypto was once again higher on Thursday, as traders continue to anticipate ne
Gareth Jenkinson9 hours agoVisa taps into Solana to widen USDC payment capabilityThe global payments firm has expanded its stablecoin settlement capability to include USDC tokens issued on the Solana blockchain.2929 Tota
Indian Finance Minister Answers Questions on Cryptocurrency Plans and Ban Proposal
Indian Finance Minister Answers Questions on Cryptocurrency Plans and Ban Proposal India’s Finance Minister Nirmala Sitharaman has answered some questions
The Largest NFT Mint in History — Bored Ape’s Otherside Virtual Land Sale Raises $320 Million
The Largest NFT Mint in History — Bored Ape"s Otherside Virtual Land Sale Raises $320 Million On Saturday, the creators of Bored Ape Yacht Club (BAYC), Yuga Labs, revealed the Ot
Aave protocol’s GHO stablecoin now live on Arbitrum
Vince Quill1 hour agoAave protocol’s GHO stablecoin now live on ArbitrumThe deployment of the GHO stablecoin on the Ethereum layer-2 network will leverage Chainlink"s CCIP interoperability protocol.410 Total views22 To