BlackTree Security · Infrastructure · Automation · AI

5,400 Small-Business Websites Became Blockchain-Backed Malware Traps

The website belonged to a clinic, plumber or small shop. The malware did not.

Netskope Threat Labs has identified more than 5,400 compromised websites that retrieve their next malicious stage from a smart contract on the BNB Smart Chain testnet. Many of the sites run WordPress, with PrestaShop also appearing in the sample. The researchers do not yet know how the sites were first breached.

The technique is called EtherHiding. It turns a blockchain into a remotely editable dead drop. A newer variant adds another boundary failure: it uses the browser’s WebRTC implementation to open an encrypted command channel that avoids the usual signalling exchange defenders expect to see.

One smart contract can change what thousands of sites deliver

Each compromised site carries a small injected loader, either inline or disguised as a package. The loader makes a JSON-RPC eth_call to a contract on the BNB Smart Chain testnet. The returned JavaScript becomes the next stage in the visitor’s browser.

In the common chain, that stage displays a ClickFix lure. The page is blurred behind a fake CAPTCHA, and the visitor is instructed to open the Windows Run dialog and paste a command. The pasted command downloads and executes the final payload.

The social-engineering step resembles the TerminalFix campaign, where a fake verification prompt persuaded users to execute the attack themselves. Here, the lure gains credibility because it appears on a real small-business website.

The blockchain gives the operator leverage. Updating one contract can change the payload retrieved by every infected site. Removing a malicious hosting account or seizing a domain does not erase a smart contract from a public chain.

The attackers chose a free developer network

The campaign uses testnet rather than the production BNB chain. Testnets exist so developers can build and change contracts without spending real cryptocurrency. Free tokens are distributed through faucets, yet the network still offers the programmable storage and distributed retrieval that make the technique attractive.

This is trusted-platform abuse, not a compromise of blockchain consensus. The same developer infrastructure that lets legitimate teams test applications provides attackers with cheap, durable payload storage. Blocking one endpoint may not be enough because a pool of RPC services can expose the same contract.

The WebRTC variant removes the handshake

WebRTC normally establishes browser video, audio or data connections through an exchange of session descriptions. That exchange, along with DNS, STUN, TURN and DTLS traffic, gives defenders artefacts to inspect.

Netskope’s stager writes its own answer. The command server’s IP address, UDP port, ICE password and DTLS certificate fingerprint are embedded in obfuscated form. The browser is given enough information to open the encrypted data channel without contacting a normal signalling server.

Code arrives over that channel, is buffered and runs when the connection closes or a timer expires. Nothing needs to be written to disk. The stager copies a Content Security Policy nonce from a legitimate script and attaches it to the malicious node so the browser treats the injected code as authorised. The node is removed immediately after execution.

The reach is already substantial

Netskope counted more than 5,400 compromised sites across over 2,200 organisations. More than 300 infected sites were active on a typical weekday, and several hundred could appear on a single day.

The victims had no obvious shared owner, sector or region. Their common value was trust. A visitor arriving at a real local business does not expect the page to retrieve executable logic from a blockchain or establish a covert peer-to-peer channel.

That makes the owners victims and unwitting distributors at the same time, a pattern BlackTree previously examined when compromised WordPress sites became infrastructure for other attacks.

What defenders should do

  • Website owners should integrity-check CMS core files, themes, plugins and JavaScript assets, including fake plugin directories and code appended to legitimate files.
  • Review administrative accounts, publishing activity and server logs to determine how the site was altered. Removing the loader without closing the initial access path invites reinfection.
  • Network teams can restrict access to the full BNB testnet RPC pool where there is no business requirement. Blocking only one observed endpoint leaves easy alternatives.
  • Monitor browsers and endpoints for JSON-RPC calls to blockchain testnets originating from ordinary business sites.
  • Look for unexpected UDP traffic and WebRTC data channels from pages that have no legitimate real-time communications function.
  • Train users that a website should not ask them to paste commands into Run, PowerShell or a terminal to prove they are human.
  • Use the indicators in Netskope’s public repository as investigation pivots, while recognising that shared blockchain infrastructure should not be treated as malicious solely by association.

This campaign combines three trusted surfaces: a real website, a public developer network and a standard browser API. Each component can look legitimate in isolation. The attack becomes visible only when defenders follow the complete sequence.

Sources and further reading

Leave a Reply

Your email address will not be published. Required fields are marked *