AI Weekly Malaysia

Back to items Summaries

ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

ID
26771
Status
summarized
Published
21 Sep 2026, 4:39 PM
Fetched
21 Sep 2026, 6:49 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/clickfix-lures-deploy-chainscript-rat.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.5
Created
21 Sep 2026, 6:50 PM
Tags
Audience
developerssaas_founders

What happened

Blackpoint APG researchers documented ChainScript, a previously undocumented RAT delivered via ClickFix lures disguised as Spotify, Zoom, and Teams installers. The malware uses a Polygon smart contract to locate its active WebSocket C2 server, enabling infrastructure rotation that resists takedown. ChainScript offers interactive shell access, file operations, screenshot capture, crypto wallet enumeration, and remote JavaScript execution on compromised Windows hosts.

Why it matters

If you distribute or recommend software downloads to users, be aware that attackers are impersonating common apps (Spotify, Zoom, Teams) via ClickFix social-engineering lures serving malicious MSI installers — there is no specific action required for most builders unless you run endpoint protection or manage employee download policies.

Discussion angle

The use of Polygon smart contracts as a C2 discovery layer is a cheap, takedown-resistant pattern worth noting — could similar decentralized coordination techniques appear in legitimate developer tooling or agent infrastructure?

Top