← Back to Feed

Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet

May 26, 2026 · Trend Micro · Severity: MEDIUM

TrendAI™ Research analyzed an intrusion where threat actors used the EtherHiding technique to route ClearFake payload delivery through smart contracts on the BNB Smart Chain testnet. The attack chain ended with two simultaneously deployed stealers, SectopRAT and ACRStealer alongside an on-chain execution tracker that confirmed each victim compromise in real time.

Key Takeaways

  • TrendAI Research analyzed an intrusion where threat actors used the EtherHiding technique to route ClearFake payload delivery through smart contracts on the BNB Smart Chain testnet.
  • The attack chain ended with two simultaneously deployed stealers, SectopRAT and ACRStealer, alongside an on-chain execution mechanism.
  • Defenders should monitor blockchain-based delivery channels, as ClearFake-style campaigns now hide command and control in smart contracts on public chains.
☕ Buy a Coffee