← Back to Feed

Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet

May 26, 2026 · Trend Micro · Severity: MEDIUM

TrendAI™ Research analyzed an intrusion where threat actors used the EtherHiding technique to route ClearFake payload delivery through smart contracts on the BNB Smart Chain testnet. The attack chain ended with two simultaneously deployed stealers, SectopRAT and ACRStealer alongside an on-chain execution tracker that confirmed each victim compromise in real time.

Key Takeaways

  • Threat actors used the EtherHiding technique to route ClearFake payload delivery through BSC testnet smart contracts.
  • The attack ended with two simultaneously deployed stealers: SectopRAT and ACRStealer.
  • Smart contracts on the BNB Smart Chain testnet were used as command-and-control infrastructure.
☕ Buy a Coffee