Skip to content
ThreatCluster

ClearFake Malware Campaign Exploits BSC Testnet for C2 Operations

First seen 28 May 2026, 16:06 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 29, 2026 at 15:45 UTC
  • ClearFake uses BSC testnet smart contracts for resilient C2 operations.
  • The campaign is difficult to disrupt due to its decentralized infrastructure.
  • Organizations are at risk as traditional takedown methods are ineffective.

The ClearFake campaign has emerged as a significant cybersecurity threat by using BNB Smart Chain (BSC) testnet smart contracts to establish a resilient command-and-control (C2) infrastructure. This innovative approach allows attackers to operate without relying on traditional servers, making it difficult for security teams to dismantle their operations. The campaign is characterized by its ability to evade conventional takedown efforts, posing a challenge for cybersecurity professionals. The use of blockchain technology in this context represents a shift in tactics for malware campaigns, highlighting the evolving landscape of cyber threats. Organizations across various sectors may be affected due to the widespread nature of the BSC testnet. Current status indicates ongoing operations, with no immediate resolution in sight.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 105d ago How this analysis works

Timeline

2026-05-28
ClearFake campaign identified
Security researchers reported the ClearFake malware campaign leveraging BSC testnet for C2 operations, complicating efforts to shut it down.
Gbhackers
2026-05-28
Malware tactics analyzed
Experts noted that ClearFake's use of blockchain technology marks a significant evolution in malware tactics, making detection and takedown more challenging.
Cybersecuritynews

More articles in this cluster (2)

Following this threat?

Track ClearFake in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed