ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
AI Summary
Threat actors are using ClickFix-style social engineering lures to distribute a new remote access trojan (RAT) named ChainScript, which provides extensive remote control capabilities including command execution, file operations, screenshot capture, and cryptocurrency wallet theft. The malware uses a malicious Windows installer disguised as legitimate software (e.g., Spotify) to deploy a Node.js-based JavaScript agent via PowerShell and VBScript stages, establishing persistence through scheduled tasks and Registry Run keys. ChainScript employs a novel C2 discovery mechanism leveraging a Polygon blockchain smart contract to dynamically rotate WebSocket-based command-and-control infrastructure, enhancing resilience against takedowns. This campaign overlaps with another abuse of HBO Max's Reddit account, distributing macOS and Windows malware such as MacSync, Atomic Stealer, and Amatera Stealer under the PasteSwitch operation.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | ComponentTask33-4d14e6ac.msi | Details → |