INTEL_REPORT
Trend Micro Research · published 5/26/2026, 12:00:00 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet TrendAI™ Research analyzed an intrusion where threat actors used the EtherHiding technique to route ClearFake payload delivery through smart contracts on the BNB Smart Chain testnet. The attack chain ended with two simultaneously deployed stealers, SectopRAT and ACRStealer alongside an on-chain execution tracker that confirmed each victim compromise in real time. Smart Contracts for C&C: How ClearF…
https://www.trendmicro.com/en_us/research/26/e/smart-contracts-for-command-and-control.html
sha256:d3d1d918d350fb1c58220140e34b1196acc60060ce7cac6010f2375c02828b32
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| firefox.exe |
| Open → |
| cve | CVE-2026-33017 | Open → |
| domain | pypi.org | Open → |
| domain | vlc.exe | Open → |
| domain | pythonw.exe | Open → |
| domain | navigator.webdriver | Open → |
| domain | portal.xdr.trendmicro.com | Open → |
| domain | bsc-testnet-rpc.publicnode.com | Open → |
| domain | navigator.useragent | Open → |
| domain | navigator.useragent.includes | Open → |
| domain | window.outerwidth | Open → |
| domain | window.outerheight | Open → |
| domain | window.safari | Open → |
| domain | ip-info.ff.avast.com | Open → |
| domain | navigator.clipboard.writetext | Open → |
| domain | put34b.camp | Open → |
| domain | chrome.exe | Open → |
| domain | dllhost.exe | Open → |
| domain | mc.yandex.ru | Open → |
| domain | helper.py | Open → |
| domain | download2324.mediafire.com | Open → |
| domain | 361e6e66.default | Open → |
| domain | libvlc.dll | Open → |
| domain | libvlccore.dll | Open → |
| domain | acrstealer.smart | Open → |
| domain | microsoftedge.exe | Open → |
| domain | iexplore.exe | Open → |
| domain | opera.exe | Open → |
| domain | brave.exe | Open → |
| domain | vivaldi.exe | Open → |
| domain | waterfox.exe | Open → |
| url | https://bsc-testnet-rpc.publicnode.com/: | Open → |
| url | https://portal.xdr.trendmicro.com/index.html#/app/ti/intelligence?intrusionSet=Smart%20Contracts%20for%20C%26C%3A%20How%20ClearFake%20Hid%20in%20Plain%20Sight%20on%20BSC%20Testnet | Open → |