A sophisticated malware scheme is leveraging blockchain technology to evade security systems, enabling cybercriminals to steal banking credentials and two-factor authentication codes from unsuspecting users. By targeting legitimate business websites, attackers are successfully integrating malicious commands to exploit vulnerabilities.
Blockchain Utilized in Cyber Attacks
Since November 2025, this ongoing campaign has been deceiving users through a fake human-verification prompt. Upon activation, malicious PowerShell commands are executed, establishing a backdoor that continuously receives updates. GuidePoint Security researchers have identified this activity, exposing 31 compromised websites and 15 Polygon smart contracts, showcasing the widespread impact across various countries and industries.
The malware’s durability is attributed to its use of blockchain, specifically a method dubbed EtherHiding. This approach allows attackers to dynamically change command-and-control servers by querying a smart contract on the Polygon network, which returns an encrypted address. This mechanism circumvents traditional security measures that block malicious domains, as infected systems can easily update their connections without modifying the malware itself.
Advanced Threat Tactics
The attackers employ JavaScript injections on legitimate sites, leading visitors to a fake CAPTCHA verification. This deceptive prompt instructs users to execute a command, initiating the malware infection. The installed malware maintains persistence through Windows Registry modifications and communicates with its control server via the Polygon blockchain.
Simultaneously, a malicious browser extension is deployed, functioning as a banking trojan. This extension is capable of logging keystrokes, capturing screen content, and extracting data from password managers and cryptocurrency wallets. Such tactics have been observed in other malware operations, underscoring the need for vigilance against unauthorized browser extensions.
Implications and Defense Strategies
Despite the sophisticated nature of this campaign, vulnerabilities within the attackers’ infrastructure have been identified. Yet, the persistent activity of certain command domains indicates that the threat remains active. Security teams are advised to focus on behavioral detection rather than solely relying on blocklists. Key indicators include unusual PowerShell activity and unauthorized blockchain queries.
To mitigate risks, organizations should restrict unapproved browser extensions and carefully monitor new installations. Resetting passwords for sensitive accounts and conducting thorough security assessments are crucial steps for affected entities. The trend of using public blockchain infrastructure highlights the evolving tactics of cybercriminals, emphasizing the importance of adaptive defense measures.
Ultimately, this development serves as a reminder for cybersecurity professionals to stay updated on emerging threats and refine detection capabilities to counteract innovative cyber attack strategies.
