Fake CAPTCHA Scam Uses Blockchain to Deliver Malware
Microsoft has uncovered a new attack technique in which hackers compromise legitimate websites and use them to display fake CAPTCHA verification screens. Instead of the usual "prove you're human" test, these fake prompts trick visitors into copying and running malicious commands on their own Windows computers.
What makes this attack notable is how the hackers hide their instructions: they store the malicious code on the BNB blockchain, a public ledger normally used for cryptocurrency transactions. Because blockchain data is decentralised and difficult to take down, this gives attackers a resilient way to serve malware instructions that's harder for defenders to block or remove compared to traditional hosting.
This technique relies on tricking users into manually executing commands, meaning awareness and caution remain a strong line of defence. Businesses should ensure staff know never to copy-paste or run commands from a website prompt, especially ones claiming to be a CAPTCHA or verification step.