Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
credential-stealer-activityphishing-campaign-intelligencecommand-and-control-methodloader-delivery-mechanism

ClearFake Uses BSC Smart Contracts and ClickFix Lures to Deliver Info-Stealers

Updated 1mo agoFirst seen May 25, 20263 sources

Researchers reported that the long-running ClearFake/EtherHiding campaign is using compromised legitimate websites, fake Google reCAPTCHA pages, and ClickFix social-engineering lures to deliver malware through BNB Smart Chain testnet smart contracts rather than conventional staging servers. Analysis from Trend Micro and Censys found the attackers embedded obfuscated JavaScript and ethers.js on hacked sites, performed browser and OS checks, and retrieved victim-specific payload logic from on-chain contracts tied to a single deployer wallet. The infrastructure included contracts for anti-analysis dispatching, separate Windows and macOS delivery, and victim tracking, making traditional takedowns and URL blocking far less effective.

The campaign delivered SectopRAT and ACRStealer to steal passwords, cookies, browser sessions, credit card data, and cryptocurrency wallet information, while macOS infections also used dynamic resolver techniques through external web services to locate command-and-control endpoints and collect host data. A related stealer campaign described by Gurucul used software-search redirection, fake MEGA Transfer pages, a Go-based loader, and an Ethereum dead-drop resolver to obtain command-and-control infrastructure, underscoring a broader shift toward blockchain-backed malware delivery and resilient C2. Defenders were advised to monitor for unexpected ethers.js usage, fake CAPTCHA assets, clipboard-driven execution prompts, and access to BSC testnet JSON-RPC services, while training users to avoid fraudulent CAPTCHA and ClickFix prompts.

Share:
ClearFake Uses BSC Smart Contracts and ClickFix Lures to Deliver Info-Stealers
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
May 28, 20261mo ago

Trend Micro analyzes ClearFake use of BSC testnet smart contracts

In May 2026, Trend Micro analyzed a ClearFake campaign that used four BNB Smart Chain testnet smart contracts tied to one deployer wallet for anti-analysis logic, Windows and macOS payload delivery, and on-chain victim tracking. The campaign delivered SectopRAT and ACRStealer and made traditional takedowns and URL blocking less effective.

ClearFake Uses BSC Testnet Smart Contracts for Takedown-Resistant Command and Control

EtherHiding campaign remains active for nearly a year

Trend Micro reported that the ClearFake malware campaign using EtherHiding and BNB Smart Chain testnet smart contracts had been active for nearly a year before its May 2026 analysis. The campaign compromised legitimate websites and used fake CAPTCHA and ClickFix lures to deliver malware.

ClearFake Uses BSC Testnet Smart Contracts for Takedown-Resistant Command and Control

Gurucul reports RemusStealer delivery via software search redirection

On May 28, 2026, Gurucul reported a campaign redirecting users searching for open-source C++ IDE software from legitimate sites to fake MEGA Transfer pages that delivered RemusStealer. The activity used CloudFront-hosted JavaScript for fingerprinting and routing and an Ethereum-based dead drop resolver for command-and-control discovery.

Remus Stealer Delivered Via Software Search Redirection | Community Portal | Gurucul
Nov 21, 20257mo ago

Censys documents blockchain-backed EtherHiding attack chain

On November 21, 2025, Censys published analysis of an EtherHiding attack chain that used Binance Smart Chain testnet smart contracts, compromised websites, fake CAPTCHA prompts, and Click-Fix lures to deliver OS-specific malware stages. The report also described macOS-specific credential theft and dynamic C2 resolution through Telegram and Steam pages.

EtherHiding: Fake CAPTCHAs, Click-Fix Lures, and Blockchain-Backed Payload Delivery - Censys
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

15 LINKEDOpen in app
Affected products
4 linked
Vlc Media PlayerWindowsMacosAmazon Cloudfront
Organizations
7 linked
Trend MicroFilezillaYandexGoogleMegaPalo Alto NetworksGurucul
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.