Known malicious kitcriticalphishing

ClearFake / ClickFix 'enterprise2026' cluster — EtherHiding BSC testnet contract reader (YARA)

family: clearfake-enterprise26-2026-08

Content match for the second stage returned by the fake plugin: a script that skips bots and WordPress admin, feed and asset URLs, then calls get() (selector 0x6d4ce63c) on a BNB Smart Chain testnet contract through a list of public RPC nodes, ABI-decodes the returned string, base64-decodes it and injects it as a script, which loads the ClickFix lure.

Anchors

YARA ruleClearFake_BscSl_BSC_Contract_Reader

Provenance

Added: 2026-09-25 12:24
Requires the get() selector, eth_call, a BSC-testnet RPC host, the ABI string decode and a base64 decode that is then injected, all together, so an ordinary web3 page reading a contract does not match. Other EtherHiding kits obfuscate their reader and are deliberately not covered by this row. First-seen contract: 0x7Fd85c090f2b35071C57a3b9FeAF462aaEb0E437.

Sightings (1)

HostScanScriptMatchWhen
osmilano.it#html99e574cc…https://osmilano.it#htmlyara2026-09-25 12:24