'EtherHiding’ hack uses Binance blockchain to extort WordPress users
Researchers at Guardio Labs have discovered a new attack known as ‘EtherHiding,’ which uses Binance Smart Chain and Bullet-Proof Hosting to serve malicious code within victims’ web browsers. Unlike an earlier suite of fake update hacks that exploited WordPress, this variant uses a new tool: Binance’s blockchain . Earlier, non-blockchain variants interrupted a webpage visit with a realistic-looking, browser-styled ‘Update’ prompt. A victim’s mouse click installed malware. Due to the cheap, fast, and poorly policed programmability of Binance Smart Chain, hackers can serve a devastating payload of code directly from this blockchain. To be clear, this is not a MetaMask attack. Hackers simply serve malicious code inside victims’ web browsers that looks like any webpage that the hacker wants to create — hosted and served in an unstoppable manner. Using Binance’s blockchain to serve code, hackers attack victims for various extortion scams. Indeed, EtherHiding ...