ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
AI-summarised brief · reviewed before publication
Threat actors are using ClickFix‑style lures to deliver a new remote‑access trojan dubbed ChainScript. The malware, also seen under names such as ComponentTask33 and OrchidViolet66, masquerades as legitimate software like Spotify, Zoom Workplace and Microsoft Teams. After a malicious MSI installer runs via msiexec.exe, it drops a Node.js runtime and launches a JavaScript agent through hidden PowerShell and VBScript stages, installing components in “%LOCALAPPDATA%” and persisting via a scheduled task with a Registry Run key fallback. ChainScript employs an EtherHiding‑style C2 discovery method that queries a Polygon smart contract to locate its WebSocket server, allowing the backend to rotate without changing the implant. The RAT offers full remote control, including CMD/PowerShell shells, file manipulation, screenshot capture, cryptocurrency wallet enumeration and remote JavaScript execution. The campaign, linked to the compromised HBO Max Reddit account, also distributes macOS stealers and crypto clippers, with 108 malicious ads posted over 48 hours in mid‑September 2026.
💡 Why It Matters
- · By offloading C2 resolution to a blockchain contract, attackers can instantly shift infrastructure, rendering traditional takedown and signature‑based defenses ineffective.
- · This technique signals a new frontier where decentralized platforms become core components of malware command structures.