Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet
May 27, 2026, 1:59 p.m.
Description
Threat actors exploited the EtherHiding technique to store ClearFake payload routing instructions within smart contracts on the BNB Smart Chain testnet, creating an immutable command-and-control infrastructure that cannot be taken down. The attack began with injected JavaScript on a compromised Swiss website that queried blockchain contracts to deliver malicious payloads. Victims passing anti-analysis checks were fingerprinted by operating system and routed to platform-specific ClickFix social engineering overlays. The campaign simultaneously deployed SectopRAT, a .NET-based remote access trojan capable of browser session hijacking, and ACRStealer, a C++ infostealer targeting credentials and cryptocurrency wallets. An on-chain execution tracker confirmed each compromise in real time. Four smart contracts shared a single deployer wallet, with the oldest deployed nearly a year before analysis, indicating a long-running, actively maintained operation.
Tags
Date
- Created: May 26, 2026, 3:20 p.m.
- Published: May 26, 2026, 3:20 p.m.
- Modified: May 27, 2026, 1:59 p.m.
Indicators
- 46add4a5fb2da6fe12759a06fe1c6bc43e987da3ea7c28bff0a7f2a349088f0d
- 9c235a84d15087719e59c09f41d43e3574de4544d490aab619184a7d65b02910
- a5691a4fc69faa4f0fe08f12347783e1dde3c617552be7efd1c5ed89a793e885
- www.badischwaendi.ch
Additional Informations
- ren.trytoken.life
- put34b.camp
- getcfgs.qen9varol.lat
- ohn.stainedunstitch.work
- afraid.veloitall.cfd
- ootid.srv-auth-dlt-msh.in.net
- root-cul.xamir3on.lat
- Switzerland