← Back to Feed
Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet
May 26, 2026 · Trend Micro · Severity: MEDIUM
TrendAI™ Research analyzed an intrusion where threat actors used the EtherHiding technique to route ClearFake payload delivery through smart contracts on the BNB Smart Chain testnet. The attack chain ended with two simultaneously deployed stealers, SectopRAT and ACRStealer alongside an on-chain execution tracker that confirmed each victim compromise in real time.
Key Takeaways
- Threat actors used the EtherHiding technique to route ClearFake payload delivery through BSC testnet smart contracts.
- The attack ended with two simultaneously deployed stealers: SectopRAT and ACRStealer.
- Smart contracts on the BNB Smart Chain testnet were used as command-and-control infrastructure.