216.73.217.22

Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet

· Published 26/05/2026 15:20 · Modified 27/05/2026 13:59

Export JSON

Essential information

Published
26/05/2026 15:20
Modified
27/05/2026 13:59
Tags
2026-05-26 acrstealer blockchain c&c bnb smart chain clearfake clickfix etherhiding infostealer sectoprat
Related entities
4 observables, 19 techniques (mitre), 2 malware, 8 others

Description

Threat actors exploited the technique to store payload routing instructions within smart contracts on the testnet, creating an immutable command-and-control infrastructure that cannot be taken down. The attack began with injected JavaScript on a compromised Swiss website that queried blockchain contracts to deliver malicious payloads. Victims passing anti-analysis checks were fingerprinted by operating system and routed to platform-specific social engineering overlays. The campaign simultaneously deployed , a .NET-based remote access trojan capable of browser session hijacking, and , a C++ targeting credentials and cryptocurrency wallets. An on-chain execution tracker confirmed each compromise in real time. Four smart contracts shared a single deployer wallet, with the oldest deployed nearly a year before analysis, indicating a long-running, actively maintained operation.

External references