Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cybercriminals Use Blockchain to Bypass Security Measures

Cybercriminals Use Blockchain to Bypass Security Measures

Posted on September 21, 2026 By CWS

A sophisticated malware scheme is leveraging blockchain technology to evade security systems, enabling cybercriminals to steal banking credentials and two-factor authentication codes from unsuspecting users. By targeting legitimate business websites, attackers are successfully integrating malicious commands to exploit vulnerabilities.

Blockchain Utilized in Cyber Attacks

Since November 2025, this ongoing campaign has been deceiving users through a fake human-verification prompt. Upon activation, malicious PowerShell commands are executed, establishing a backdoor that continuously receives updates. GuidePoint Security researchers have identified this activity, exposing 31 compromised websites and 15 Polygon smart contracts, showcasing the widespread impact across various countries and industries.

The malware’s durability is attributed to its use of blockchain, specifically a method dubbed EtherHiding. This approach allows attackers to dynamically change command-and-control servers by querying a smart contract on the Polygon network, which returns an encrypted address. This mechanism circumvents traditional security measures that block malicious domains, as infected systems can easily update their connections without modifying the malware itself.

Advanced Threat Tactics

The attackers employ JavaScript injections on legitimate sites, leading visitors to a fake CAPTCHA verification. This deceptive prompt instructs users to execute a command, initiating the malware infection. The installed malware maintains persistence through Windows Registry modifications and communicates with its control server via the Polygon blockchain.

Simultaneously, a malicious browser extension is deployed, functioning as a banking trojan. This extension is capable of logging keystrokes, capturing screen content, and extracting data from password managers and cryptocurrency wallets. Such tactics have been observed in other malware operations, underscoring the need for vigilance against unauthorized browser extensions.

Implications and Defense Strategies

Despite the sophisticated nature of this campaign, vulnerabilities within the attackers’ infrastructure have been identified. Yet, the persistent activity of certain command domains indicates that the threat remains active. Security teams are advised to focus on behavioral detection rather than solely relying on blocklists. Key indicators include unusual PowerShell activity and unauthorized blockchain queries.

To mitigate risks, organizations should restrict unapproved browser extensions and carefully monitor new installations. Resetting passwords for sensitive accounts and conducting thorough security assessments are crucial steps for affected entities. The trend of using public blockchain infrastructure highlights the evolving tactics of cybercriminals, emphasizing the importance of adaptive defense measures.

Ultimately, this development serves as a reminder for cybersecurity professionals to stay updated on emerging threats and refine detection capabilities to counteract innovative cyber attack strategies.

Cyber Security News Tags:banking security, Blockchain, cyber attack, Cybersecurity, GuidePoint Security, Hacking, Malware, security measures, smart contracts, two-factor authentication

Post navigation

Previous Post: CrowdSec Confirms Source Code Breach in Recent Attack

Related Posts

New DNS Malware Detour Dog Delivers Strela Stealer Using DNS TXT Records New DNS Malware Detour Dog Delivers Strela Stealer Using DNS TXT Records Cyber Security News
CISA Flags Critical Microsoft Defender Vulnerabilities CISA Flags Critical Microsoft Defender Vulnerabilities Cyber Security News
Cybercriminals Exploit AI for Sophisticated Scams Cybercriminals Exploit AI for Sophisticated Scams Cyber Security News
Critical FreeBSD Flaw Risks System Security Breach Critical FreeBSD Flaw Risks System Security Breach Cyber Security News
Jenkins Security Flaws Pose Major XSS Threats Jenkins Security Flaws Pose Major XSS Threats Cyber Security News
New Phishing Tactic Utilizes Google Cloud for Remcos RAT New Phishing Tactic Utilizes Google Cloud for Remcos RAT Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cybercriminals Use Blockchain to Bypass Security Measures
  • CrowdSec Confirms Source Code Breach in Recent Attack
  • WaterPlum Hackers Exploit Job Interviews to Steal Cryptocurrency
  • Critical Linux Kernel Vulnerabilities Demand Immediate Attention
  • ChainScript RAT Uses Polygon to Evade Detection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cybercriminals Use Blockchain to Bypass Security Measures
  • CrowdSec Confirms Source Code Breach in Recent Attack
  • WaterPlum Hackers Exploit Job Interviews to Steal Cryptocurrency
  • Critical Linux Kernel Vulnerabilities Demand Immediate Attention
  • ChainScript RAT Uses Polygon to Evade Detection

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark