ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
- ID
- 26771
- Status
- summarized
- Published
- 21 Sep 2026, 4:39 PM
- Fetched
- 21 Sep 2026, 6:49 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/clickfix-lures-deploy-chainscript-rat.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.5
- Created
- 21 Sep 2026, 6:50 PM
- Tags
- Audience
- developerssaas_founders
What happened
Blackpoint APG researchers documented ChainScript, a previously undocumented RAT delivered via ClickFix lures disguised as Spotify, Zoom, and Teams installers. The malware uses a Polygon smart contract to locate its active WebSocket C2 server, enabling infrastructure rotation that resists takedown. ChainScript offers interactive shell access, file operations, screenshot capture, crypto wallet enumeration, and remote JavaScript execution on compromised Windows hosts.
Why it matters
If you distribute or recommend software downloads to users, be aware that attackers are impersonating common apps (Spotify, Zoom, Teams) via ClickFix social-engineering lures serving malicious MSI installers — there is no specific action required for most builders unless you run endpoint protection or manage employee download policies.
Discussion angle
The use of Polygon smart contracts as a C2 discovery layer is a cheap, takedown-resistant pattern worth noting — could similar decentralized coordination techniques appear in legitimate developer tooling or agent infrastructure?