EtherHiding: Fake CAPTCHAs, Click-Fix Lures, and Blockchain-Backed Payload Delivery
ID: 6b09bdf0-07c4-54fe-a16e-d82e84e37abb
STIX ID: report--6b09bdf0-07c4-54fe-a16e-d82e84e37abb
Feed Name: Censys Blog
Date Published: 2025-11-21
Date Updated: 2026-04-27
Author: Andrew Northern; Principal Security Researcher
EtherHiding is a web-delivered malware campaign that uses fake CAPTCHA lures and smart-contract storage on the Binance Smart Chain testnet to stage and rotate payloads without changing compromised websites. Injected pages load ethers.js and perform on-chain eth_call lookups to retrieve OS-specific JavaScript which populates the clipboard with attacker commands; victims who paste into Terminal (macOS) or the Run dialog (Windows) trigger curl-to-bash or MSHTA download-execute flows that deploy credential-stealing and backdoor components (notably commodity stealers like Amos and Vidar). Censys telemetry shows widespread fake CAPTCHA reuse and recurring contract addresses, and the report provides behavioral detection signals and hunting guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
