Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cybercriminals Use Blockchain to Bypass Security Measures

Cybercriminals Use Blockchain to Bypass Security Measures

Posted on September 21, 2026 By CWS

A sophisticated malware scheme is leveraging blockchain technology to evade security systems, enabling cybercriminals to steal banking credentials and two-factor authentication codes from unsuspecting users. By targeting legitimate business websites, attackers are successfully integrating malicious commands to exploit vulnerabilities.

Blockchain Utilized in Cyber Attacks

Since November 2025, this ongoing campaign has been deceiving users through a fake human-verification prompt. Upon activation, malicious PowerShell commands are executed, establishing a backdoor that continuously receives updates. GuidePoint Security researchers have identified this activity, exposing 31 compromised websites and 15 Polygon smart contracts, showcasing the widespread impact across various countries and industries.

The malware’s durability is attributed to its use of blockchain, specifically a method dubbed EtherHiding. This approach allows attackers to dynamically change command-and-control servers by querying a smart contract on the Polygon network, which returns an encrypted address. This mechanism circumvents traditional security measures that block malicious domains, as infected systems can easily update their connections without modifying the malware itself.

Advanced Threat Tactics

The attackers employ JavaScript injections on legitimate sites, leading visitors to a fake CAPTCHA verification. This deceptive prompt instructs users to execute a command, initiating the malware infection. The installed malware maintains persistence through Windows Registry modifications and communicates with its control server via the Polygon blockchain.

Simultaneously, a malicious browser extension is deployed, functioning as a banking trojan. This extension is capable of logging keystrokes, capturing screen content, and extracting data from password managers and cryptocurrency wallets. Such tactics have been observed in other malware operations, underscoring the need for vigilance against unauthorized browser extensions.

Implications and Defense Strategies

Despite the sophisticated nature of this campaign, vulnerabilities within the attackers’ infrastructure have been identified. Yet, the persistent activity of certain command domains indicates that the threat remains active. Security teams are advised to focus on behavioral detection rather than solely relying on blocklists. Key indicators include unusual PowerShell activity and unauthorized blockchain queries.

To mitigate risks, organizations should restrict unapproved browser extensions and carefully monitor new installations. Resetting passwords for sensitive accounts and conducting thorough security assessments are crucial steps for affected entities. The trend of using public blockchain infrastructure highlights the evolving tactics of cybercriminals, emphasizing the importance of adaptive defense measures.

Ultimately, this development serves as a reminder for cybersecurity professionals to stay updated on emerging threats and refine detection capabilities to counteract innovative cyber attack strategies.

Cyber Security News Tags:banking security, Blockchain, cyber attack, Cybersecurity, GuidePoint Security, Hacking, Malware, security measures, smart contracts, two-factor authentication

Post navigation

Previous Post: CrowdSec Confirms Source Code Breach in Recent Attack
Next Post: Rust Developers Face Credential Theft Threat

Related Posts

Russian Hackers Exploit New CTRL Toolkit for RDP Attacks Russian Hackers Exploit New CTRL Toolkit for RDP Attacks Cyber Security News
New Rust-Based macOS Threat Uses Telegram for Data Theft New Rust-Based macOS Threat Uses Telegram for Data Theft Cyber Security News
Canada Police Dismantles TradeOgre Platform That Stolen 56 Million Dollars in Cryptocurrency Canada Police Dismantles TradeOgre Platform That Stolen 56 Million Dollars in Cryptocurrency Cyber Security News
MAD-CAT Meow Attack Tool to Simulate Real-World Data Corruption Attacks MAD-CAT Meow Attack Tool to Simulate Real-World Data Corruption Attacks Cyber Security News
QuasarRAT Core Functionalities Along with Encrypted Configuration and Obfuscation Techniques Exposed QuasarRAT Core Functionalities Along with Encrypted Configuration and Obfuscation Techniques Exposed Cyber Security News
Data Breach at Texas Gas Station Operator Exposes Info of 377,000+ Customers Data Breach at Texas Gas Station Operator Exposes Info of 377,000+ Customers Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New PoC Targets Microsoft Defender with DoS Attack
  • Rust Developers Face Credential Theft Threat
  • Cybercriminals Use Blockchain to Bypass Security Measures
  • CrowdSec Confirms Source Code Breach in Recent Attack
  • WaterPlum Hackers Exploit Job Interviews to Steal Cryptocurrency

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New PoC Targets Microsoft Defender with DoS Attack
  • Rust Developers Face Credential Theft Threat
  • Cybercriminals Use Blockchain to Bypass Security Measures
  • CrowdSec Confirms Source Code Breach in Recent Attack
  • WaterPlum Hackers Exploit Job Interviews to Steal Cryptocurrency

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark