Known malicious kitcriticalphishing
ClearFake / ClickFix 'enterprise2026' cluster — EtherHiding BSC testnet contract reader (YARA)
family: clearfake-enterprise26-2026-08
Content match for the second stage returned by the fake plugin: a script that skips bots and WordPress admin, feed and asset URLs, then calls get() (selector 0x6d4ce63c) on a BNB Smart Chain testnet contract through a list of public RPC nodes, ABI-decodes the returned string, base64-decodes it and injects it as a script, which loads the ClickFix lure.
Anchors
YARA ruleClearFake_BscSl_BSC_Contract_Reader
Provenance
Added: 2026-09-25 12:24
Requires the get() selector, eth_call, a BSC-testnet RPC host, the ABI string decode and a base64 decode that is then injected, all together, so an ordinary web3 page reading a contract does not match. Other EtherHiding kits obfuscate their reader and are deliberately not covered by this row. First-seen contract: 0x7Fd85c090f2b35071C57a3b9FeAF462aaEb0E437.
Sightings (1)
| Host | Scan | Script | Match | When |
|---|---|---|---|---|
| osmilano.it#html | 99e574cc… | https://osmilano.it#html | yara | 2026-09-25 12:24 |