Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet
Essential information
- Published
- 26/05/2026 15:20
- Modified
- 27/05/2026 13:59
- Tags
- 2026-05-26 acrstealer blockchain c&c bnb smart chain clearfake clickfix etherhiding infostealer sectoprat
- Related entities
- 4 observables, 19 techniques (mitre), 2 malware, 8 others
Description
Threat actors exploited the EtherHiding technique to store ClearFake payload routing instructions within smart contracts on the BNB Smart Chain testnet, creating an immutable command-and-control infrastructure that cannot be taken down. The attack began with injected JavaScript on a compromised Swiss website that queried blockchain contracts to deliver malicious payloads. Victims passing anti-analysis checks were fingerprinted by operating system and routed to platform-specific ClickFix social engineering overlays. The campaign simultaneously deployed SectopRAT, a .NET-based remote access trojan capable of browser session hijacking, and ACRStealer, a C++ infostealer targeting credentials and cryptocurrency wallets. An on-chain execution tracker confirmed each compromise in real time. Four smart contracts shared a single deployer wallet, with the oldest deployed nearly a year before analysis, indicating a long-running, actively maintained operation.