importantSYS.SOURCE: The Hacker News• 2026-09-21T14:09:38+05:30
Threat Actors Deploy ChainScript RAT via ClickFix Lures Using Polygon for C2 Rotation
Threat actors are using ClickFix lures to deploy the ChainScript RAT, which leverages a Polygon smart contract for decentralized C2 infrastructure rotation. The malware employs EtherHiding techniques to evade detection, enabling dynamic C2 server redirection and persistent remote access.
Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript.
"ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while presenting itself as Spotify, Zoom Workplace, and Microsoft Teams software," Blackpoint Adversary Pursuit Group (APG)
*** END OF TRANSMISSION ***