ClearFake Malware Campaign Exploits BSC Testnet for C2 Operations
Article Content
- •ClearFake uses BSC testnet smart contracts for resilient C2 operations.
- •The campaign is difficult to disrupt due to its decentralized infrastructure.
- •Organizations are at risk as traditional takedown methods are ineffective.
The ClearFake campaign has emerged as a significant cybersecurity threat by using BNB Smart Chain (BSC) testnet smart contracts to establish a resilient command-and-control (C2) infrastructure. This innovative approach allows attackers to operate without relying on traditional servers, making it difficult for security teams to dismantle their operations. The campaign is characterized by its ability to evade conventional takedown efforts, posing a challenge for cybersecurity professionals. The use of blockchain technology in this context represents a shift in tactics for malware campaigns, highlighting the evolving landscape of cyber threats. Organizations across various sectors may be affected due to the widespread nature of the BSC testnet. Current status indicates ongoing operations, with no immediate resolution in sight.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track ClearFake in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
ClearFake Campaigns Utilize WordlistLoader to Distribute Amatera Infostealer A new malware campaign identified as ClearFake employs a loader named WordlistLoader to deploy the Amatera infostealer, targeting Windows users. This loader reconstructs shellcode from encoded English words, enhancing its evasion capabilities against detection. The Amatera infostealer has advanced features, including…
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique Since February 2026, threat actors have been exploiting the trusted Node.js runtime to deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels. The technique leverages node.exe, a legitimate and signed developer tool, allowing attackers to run interpreted scripts…