← Back to Feed
Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet
May 26, 2026 · Trend Micro · Severity: MEDIUM
TrendAI™ Research analyzed an intrusion where threat actors used the EtherHiding technique to route ClearFake payload delivery through smart contracts on the BNB Smart Chain testnet. The attack chain ended with two simultaneously deployed stealers, SectopRAT and ACRStealer alongside an on-chain execution tracker that confirmed each victim compromise in real time.
Key Takeaways
- TrendAI Research analyzed an intrusion where threat actors used the EtherHiding technique to route ClearFake payload delivery through smart contracts on the BNB Smart Chain testnet.
- The attack chain ended with two simultaneously deployed stealers, SectopRAT and ACRStealer, alongside an on-chain execution mechanism.
- Defenders should monitor blockchain-based delivery channels, as ClearFake-style campaigns now hide command and control in smart contracts on public chains.