HomeSecurityClickFix attacks distribute new ChainScript RAT

ClickFix attacks distribute new ChainScript RAT

ChainScript RAT is a new Remote Access Trojan discovered by security researchers that uses ClickFix techniques to trick victims into gaining full access to their systems. The malware is notable for using blockchain infrastructure — specifically the Polygon network — to dynamically locate command and control ( C2 ) servers , making it extremely difficult for traditional security solutions to counter. The discovery, by the Blackpoint Adversary Pursuit Group (APG) , is indicative of the increasing sophistication of modern cyberthreats.

ChainScript RAT ClickFix attack with Polygon blockchain C2 infrastructure

According to researchers Sam Decker, Andi Ursry , and Nevan Beal of Blackpoint APG, the ChainScript RAT has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared , and OrchidViolet66. It also presents itself to victims as legitimate software for well-known applications, such as Spotify, Zoom Workplace , and Microsoft Teams, exploiting users’ trust in these platforms. This social engineering tactic is a key element of its success.

What makes ChainScript RAT particularly dangerous is its adoption of the EtherHiding for command-and-control (C2). Specifically, the malware uses a Polygon smart contract to detect its active WebSocket infrastructure. This approach allows attackers to change C2 servers without having to modify the malware itself, rendering traditional detection methods based on indicators of compromise ineffective.

See also: ClickFix: 5,400 hacked websites use blockchain

How the ChainScript RAT works: The attack chain

The starting point of the attack is a ClickFix lure — a social engineering technique that tricks the user into executing malicious commands. The victim is led to download and run a malicious Windows installer via the msiexec.exe. The installer file (ComponentTask33-4d14e6ac.msi), disguised as Spotify, installs the Node.js runtime and launches the ChainScript JavaScript agent via hidden PowerShell and VBScript.

The PowerShell script drops various components — runtime, agent source, configuration, and helper binaries — into paths that mimic Microsoft folders within the %LOCALAPPDATA% directory. The VBScript acts as the main launcher for the ChainScript RAT . Once executed, the agent installs user-level persistence via a scheduled task with a fallback to the Registry Run key , ensuring that the malware is automatically restarted after each system reboot.

Once installed, the ChainScript RAT connects to the C2 server via WebSockets and retrieves additional commands, giving the attacker direct control of the compromised system. Supported commands include interactive CMD and PowerShell, file operations, taking screenshots, deploying payloads, enumerating cryptocurrency wallets (both desktop applications and browser extensions), and remote JavaScript. Additionally, the malware can self-update and remove persistence when needed.

ChainScript RAT - SecNews.gr

ChainScript RAT and Blockchain: The New Era of Detection Evasion

The use of the Polygon blockchain as a C2 discovery mechanism represents a significant evolution in cybercriminal tactics. By separating the discovery backend from the malware itself and using the Polygon smart contract as an external resolver, the operator can redirect infected hosts to new infrastructure, while maintaining the same implant and reconnect flow. This means that even if authorities or security companies manage to take down one C2 server, the malware simply searches for the next one via the blockchain.

Blackpoint APG notes that the ChainScript RAT reflects an emerging malware pattern that uses development frameworks and blockchain-based C2 discovery to enable infrastructure switching and complicate traditional indicator-based detection. This trend is particularly worrisome, as it renders traditional security solutions based on IP blacklists and domain blocking nearly ineffective.

See also: Over 250 ClickFix Domains Hide Malware Baits on macOS

The EtherHidingused by the ChainScript RAT is not entirely new — it has been seen in other malware families in recent months. However, its combination with ClickFix lures, Node.js runtimes , and multiple build names is a particularly sophisticated approach. The fact that the malware masquerades as popular applications like Spotify and Microsoft Teams significantly increases the chances of the attack being successful, especially in corporate environments where these applications are used daily.

PasteSwitch and ChainScript RAT: The Reddit Campaign

Alongside the discovery of the ChainScript RAT , a related campaign codenamed PasteSwitch by Hudson Rock and ADAMnetworks came to light . In this case, malicious actors compromised the official HBO Max Reddit account ( u/hbomax ) and used it to promote malicious ads that launched ClickFix attacks on Windows and macOS devices . Over a 48-hour period in mid -September 2026, the verified account served 108 malicious ads .

On macOS , the PasteSwitch campaign delivered MacSync , Atomic macOS Stealer (AMOS) , and fake cryptocurrency wallet apps designed to steal recovery phrases. On Windows , it distributed Amatera Stealer and cryptocurrency clippers such as AnimateClipper and ZigClipper . According to data from Seqrite Labs , MacSync infections were concentrated primarily in the US , followed by the UK , Germany , Japan , Canada , France , Singapore , Australia , India , and the Netherlands .

ACR Stealer ClickFix attack stealing Microsoft 365 tokens

Seqrite Labs researcher Chandra Kant Bauri notes that MacSync campaigns primarily target areas with extensive enterprise macOS usage , technology and software development sectors, as well as active cryptocurrency or Web3 communities . This suggests that attackers are strategically choosing their targets based on potential financial return.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

How to protect yourself from ChainScript RAT and ClickFix attacks

Countering threats like the ChainScript RATrequires a multi-layered approach. First, organizations must train their users to recognize ClickFix techniques — particularly fake instructions that request execution of commands in PowerShell or CMD. Second, using Endpoint Detection and Response (EDR) that can detect suspicious behavior — such as executing msiexec.exe from unexpected sources — is critical. Third, monitoring network traffic for WebSocket connections to blockchain endpoints can reveal infections.

See also: Mac: New ClickFix attack abuses Script Editor

Additionally, system administrators should implement policies that restrict the installation of software from unauthorized sources and monitor the creation of scheduled tasks and modifications to the Registry Run key. Using application whitelisting can also prevent the execution of unauthorized applications, even if they are disguised as known software. Finally, regularly updating security solutions and monitoring alerts from trusted sources such as Blackpoint APG is essential to timely address new threats.

The emergence of the ChainScript RAT highlights a worrying trend: cybercriminals are adopting increasingly sophisticated techniques, combining social engineering, decentralized infrastructure, and modern development frameworks to create malware that is difficult to detect and even harder to eradicate. The cybersecurity community must remain vigilant and develop new detection methods that do not rely solely on traditional breach indicators.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS