Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet

May 27, 2026, 1:59 p.m.

Description

Threat actors exploited the EtherHiding technique to store ClearFake payload routing instructions within smart contracts on the BNB Smart Chain testnet, creating an immutable command-and-control infrastructure that cannot be taken down. The attack began with injected JavaScript on a compromised Swiss website that queried blockchain contracts to deliver malicious payloads. Victims passing anti-analysis checks were fingerprinted by operating system and routed to platform-specific ClickFix social engineering overlays. The campaign simultaneously deployed SectopRAT, a .NET-based remote access trojan capable of browser session hijacking, and ACRStealer, a C++ infostealer targeting credentials and cryptocurrency wallets. An on-chain execution tracker confirmed each compromise in real time. Four smart contracts shared a single deployer wallet, with the oldest deployed nearly a year before analysis, indicating a long-running, actively maintained operation.

Date

  • Created: May 26, 2026, 3:20 p.m.
  • Published: May 26, 2026, 3:20 p.m.
  • Modified: May 27, 2026, 1:59 p.m.

Indicators

  • 46add4a5fb2da6fe12759a06fe1c6bc43e987da3ea7c28bff0a7f2a349088f0d
  • 9c235a84d15087719e59c09f41d43e3574de4544d490aab619184a7d65b02910
  • a5691a4fc69faa4f0fe08f12347783e1dde3c617552be7efd1c5ed89a793e885
  • www.badischwaendi.ch

Additional Informations

  • ren.trytoken.life
  • put34b.camp
  • getcfgs.qen9varol.lat
  • ohn.stainedunstitch.work
  • afraid.veloitall.cfd
  • ootid.srv-auth-dlt-msh.in.net
  • root-cul.xamir3on.lat
  • Switzerland