started · updated
EtherHiding malware uses BNB Smart Chain for command instructions and local AI for phishing attacks
A new malware campaign known as "EtherHiding" is utilizing the BNB Smart Chain to host command-and-control instructions. By using the blockchain as a persistent storage medium, attackers make it significantly more difficult for security services to identify and attribute malicious activity.
The campaign specifically targets Windows and macOS users through malware such as Lumma Stealer and AsyncRAT. Microsoft has issued warnings that the scale of this threat could affect thousands of users daily.
Additionally, cybersecurity reports indicate that threat groups, including Kimsuky, are integrating local AI models—using tools like Ollama and GPT4All—to automate the creation of highly convincing phishing documents. By running these language models locally rather than via cloud APIs, attackers can avoid typical detection patterns associated with cloud-based AI interactions.
Entities
AsyncRAT · BNB Smart Chain · Kimsuky · Lumma Stealer · Microsoft