ClearFake Abuses BSC Testnet Contracts for Resilient C2 Operations
ID: 1be73234-6099-5018-b1ff-cecb7f46f283
STIX ID: report--1be73234-6099-5018-b1ff-cecb7f46f283
Feed Name: GBHackers
ClearFake is an active, ongoing campaign that leverages BNB Smart Chain testnet smart contracts as an immutable C2 to deliver browser-executed malicious JavaScript which fetches payloads directly from on-chain storage; the campaign deploys SectopRAT (a .NET RAT) and ACRStealer (a C++ infostealer), uses social-engineering overlays and clipboard hijacking on Windows and macOS, employs fileless and DLL sideloading techniques, and even records successful infections to a tracking smart contract—demonstrating a sophisticated, resilient blockchain-based C2 that evades traditional takedown methods.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
