By Interestana AI Editorial — AI-drafted, human-overseen. How we report
ClickFix Lures Deploy ChainScript RAT Via Polygon

Threat actors are employing ClickFix-like lures to distribute a newly identified remote access trojan (RAT) named ChainScript. This RAT has been observed under various build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66. In its deceptive presentation, ChainScript masquerades as legitimate software such as Spotify, Zoom Workplace, and Microsoft Teams, aiming to trick unsuspecting users into execution. The discovery and analysis of ChainScript were detailed by Blackpoint Adversary Pursuit Group (APG).
ChainScript's operational methodology involves leveraging the Polygon network, a layer-2 scaling solution for Ethereum, to rotate its command and control (C2) infrastructure. This tactic makes it significantly more challenging for security researchers and defenders to track and disrupt the malware's communication channels. By utilizing the decentralized nature of blockchain technology, specifically the Polygon network, the threat actors can dynamically change the IP addresses and domains associated with their C2 servers, thereby evading detection and blocking efforts. This sophisticated approach to C2 management highlights an evolving trend in malware deployment, where attackers are increasingly integrating blockchain technologies to enhance their operational security and persistence.
The initial infection vector for ChainScript appears to be through phishing campaigns that utilize "ClickFix" lures. These lures are designed to mimic legitimate software update notifications or critical system messages, prompting users to click on malicious links or download infected files. Once executed, ChainScript establishes a persistent presence on the compromised system, allowing attackers to remotely control the infected device. The capabilities of ChainScript, as a RAT, likely include data exfiltration, keystroke logging, remote command execution, and potentially the deployment of additional malware payloads. The use of multiple build names and deceptive software identities further complicates the attribution and detection process, as security tools may struggle to identify the same underlying threat across different disguises.
Blackpoint APG's analysis indicates that the threat actors behind ChainScript are actively developing and refining their tools and techniques. The integration of Polygon for C2 rotation represents a notable advancement in their evasion strategies. This method allows for rapid changes in C2 infrastructure, making it difficult for security teams to maintain up-to-date blocklists. The implications of this discovery are significant for cybersecurity professionals, underscoring the need for enhanced vigilance against sophisticated phishing attacks and the adoption of advanced threat detection mechanisms capable of identifying anomalies in network traffic, even when C2 communications are obfuscated through blockchain technologies. Further research is expected to uncover more details about ChainScript's full capabilities and the extent of its deployment.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.