ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Blackpoint details new ChainScript RAT spread via ClickFix lures that uses a Polygon smart contract to rotate C2 infrastructure.
Blackpoint's Adversary Pursuit Group describes ChainScript, a previously undocumented full-featured RAT masquerading as Spotify, Zoom Workplace and Microsoft Teams installers. It uses an EtherHiding-style technique, querying a Polygon smart contract to locate active WebSocket C2 servers, letting operators rotate infrastructure while resisting takedowns. The chain starts with ClickFix lures leading to msiexec execution, Node.js runtime deployment and hidden PowerShell/VBScript stages, with scheduled-task and Registry Run key persistence. Separately, HBO Max's verified Reddit account served 108 malicious ads in 48 hours pushing MacSync, Atomic macOS Stealer, Amatera Stealer and crypto clippers.