Threats Tagged 'bnb smart chain'
View all threats tagged with 'bnb smart chain'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'bnb smart chain'
Click on any threat for detailed analysis and mitigation recommendations
0 Cisco Talos identified a malware infection chain involving WebDAV-based DLL execution delivering the Amatera stealer and secondary payloads including ZigCryptoStealer and NetSupport Manager. The infection chain uses a Cloudflare Worker to inject JavaScript stored on BNB Smart Chain and a fake CAPTCHA prompt to trick victims into executing the malware. Two distinct DLL loaders named "verification.google" and "pf.ch" were observed, each deploying different secondary payloads. The "verification.google" loader installed NetSupport Manager with a command-and-control server IP linked to Russia, suggesting a Russian threat actor. The infection was first observed in April 2026 targeting a Ukrainian government organization but is assessed as not specifically targeted. Multiple infection chains delivering Amatera stealer have been documented, but no direct infrastructure links were found between them. The threat involves credential and cryptocurrency theft through sophisticated multi-stage delivery mechanisms. Join the discussion | Cisco Talos | 09/08/2026, 12:22:29 UTC Added: 09/08/2026, 10:06:36 UTC |
Threat actors exploited the EtherHiding technique to store ClearFake payload routing instructions within smart contracts on the BNB Smart Chain testnet, creating an immutable command-and-control infrastructure that cannot be taken down. The attack began with injected JavaScript on a compromised Swiss website that queried blockchain contracts to deliver malicious payloads. Victims passing anti-analysis checks were fingerprinted by operating system and routed to platform-specific ClickFix social engineering overlays. The campaign simultaneously deployed SectopRAT, a .NET-based remote access trojan capable of browser session hijacking, and ACRStealer, a C++ infostealer targeting credentials and cryptocurrency wallets. An on-chain execution tracker confirmed each compromise in real time. Four smart contracts shared a single deployer wallet, with the oldest deployed nearly a year before analysis, indicating a long-running, actively maintained operation. Join the discussion | AlienVault OTX General | 05/26/2026, 15:20:06 UTC Added: 05/27/2026, 14:03:32 UTC |
0 An active campaign targets Trust Wallet users through malicious QR codes distributed via Telegram, exploiting deep link mechanisms to redirect victims to Netlify-hosted phishing domains. The attack masquerades as a legitimate USDT transfer interface but covertly triggers an ERC-20 approve() transaction, granting unlimited token allowance to an attacker-controlled contract on BNB Smart Chain. This enables persistent fund drainage without further victim interaction. The modular drainer architecture uses config.js for control parameters and main.js for execution logic, with integrated Telegram bot infrastructure providing real-time transaction monitoring. Analysis confirms 52 transaction notifications indicating active exploitation. The campaign employs social engineering through a deceptive dollar-one illusion where victims believe they are initiating small transactions while actually granting unlimited wallet access. Multiple cloned phishing domains demonstrate scalable deployment within a Drainer-as-a-Servic Join the discussion | AlienVault OTX General | 04/15/2026, 17:16:15 UTC Added: 04/15/2026, 17:32:23 UTC |
A sophisticated phishing campaign impersonating Tesseract OCR was discovered, utilizing typosquatting and ClickFix techniques. The attack chain, named OCRFix, employed multi-stage malware deployments with heavy obfuscation and defense evasion techniques, including EtherHiding. The campaign used BNB Smart Chain TestNet to hide C2 domains through smart contracts. The malware delivery process involved three stages: a loader, a secondary loader for persistence, and a bot listener. The final payload connected to a bot control panel, allowing attackers to manage infected hosts and deploy additional malware. The campaign demonstrated a combination of simple initial access methods with complex delivery chains, highlighting the ongoing effectiveness of techniques like ClickFix and the importance of robust phishing defenses. Join the discussion | AlienVault OTX General | 02/27/2026, 09:28:41 UTC Added: 02/27/2026, 09:55:15 UTC |
UNC5142, a financially motivated threat actor, has been tracked since late 2023 for abusing blockchain technology to distribute infostealers. The group exploits vulnerable WordPress sites and employs the 'EtherHiding' technique to obscure malicious code on the BNB Smart Chain. Their infection chain involves a multistage JavaScript downloader called CLEARSHORT, compromised WordPress sites, and smart contracts. UNC5142 has evolved its tactics, using a three-level smart contract system for dynamic payload delivery and abusing legitimate services like Cloudflare Pages. The group has distributed various infostealers, including ATOMIC, VIDAR, LUMMAC.V2, and RADTHIEF. Their operations have impacted multiple industries and geographic regions, with approximately 14,000 compromised web pages identified as of June 2025. Join the discussion | AlienVault OTX General | 10/16/2025, 17:53:02 UTC Added: 10/16/2025, 21:28:49 UTC |
Showing 1 to 5 of 5 results