ChainScript RAT Uses Polygon Smart Contracts For Flexible Command Infrastructure

ChainScript RAT Uses Polygon Smart Contracts For Flexible Command Infrastructure

Threat actors are using ClickFix-style social engineering lures to distribute a newly identified remote access trojan (RAT) named ChainScript, according to security researchers. The malware has been observed operating under multiple build names while disguising itself as legitimate software applications, including Spotify, Zoom Workplace, and Microsoft Teams. Researchers from Blackpoint Adversary Pursuit Group (APG) identified the activity and found that ChainScript uses a blockchain-based approach to locate its command and control (C2) infrastructure, allowing operators to change backend servers while maintaining communication with infected systems.

ChainScript has appeared under names such as ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66. According to researchers Sam Decker, Andi Ursry, and Nevan Beal, the malware presents itself as trusted applications to encourage users to install malicious files. The attack begins with a ClickFix-style lure that directs users toward downloading and executing a malicious Windows installer through the legitimate Windows utility msiexec.exe. The installer, named ComponentTask33-4d14e6ac.msi, is disguised as Spotify software and deploys the Node.js runtime before launching the ChainScript JavaScript-based agent through hidden PowerShell and VBScript execution stages. The malware uses an EtherHiding-style command discovery technique that relies on a Polygon smart contract to identify its active WebSocket-based C2 infrastructure. Instead of storing fixed server information directly inside the malware, ChainScript retrieves updated connection details through the blockchain network. Researchers said this approach allows operators to redirect infected systems to new infrastructure while reducing the effectiveness of traditional security methods that depend on known indicators such as fixed domains or IP addresses. The technique provides greater flexibility for maintaining communication channels and complicates efforts to track or disrupt malicious infrastructure.

Once installed, ChainScript provides extensive remote access capabilities to operators. The RAT can execute interactive commands through CMD and PowerShell, manage files, capture screenshots, deploy additional payloads, inspect cryptocurrency wallets across desktop applications and browser extensions, and execute JavaScript remotely. The malware establishes user-level persistence through scheduled tasks and includes a Registry Run key fallback mechanism. After execution, the ChainScript agent connects with the C2 server through WebSockets and receives additional instructions, including commands that allow it to update itself or remove persistence mechanisms from the compromised device. Blackpoint researchers said ChainScript represents a growing trend where malware operators combine modern development frameworks with decentralized technologies to create adaptable attack infrastructure. By separating malware functionality from infrastructure discovery, attackers can maintain operational continuity even when individual servers are identified or disrupted. The use of blockchain-based C2 discovery demonstrates how threat actors continue to explore new methods to improve malware resilience and avoid conventional detection approaches.

The ChainScript disclosure comes alongside increased activity involving ClickFix techniques, where attackers use fake instructions or misleading downloads to convince users to execute malicious commands themselves. Recent campaigns have abused trusted online platforms and impersonated popular services to distribute information-stealing malware targeting both Windows and macOS users. Security researchers have also observed campaigns involving compromised social media accounts that promoted malicious advertisements leading to ClickFix attacks. One such campaign, tracked as PasteSwitch, used a compromised HBO Max Reddit account to distribute malicious ads that delivered malware including MacSync, Atomic macOS Stealer (AMOS), Amatera Stealer, and cryptocurrency clipping tools.

Security researchers noted that these campaigns often rely on realistic branding and trusted platforms to reduce user suspicion. Other ClickFix operations have used fake software download pages, including misleading Codex installation experiences, to trick macOS users into pasting malicious commands into Terminal. These attacks demonstrate how threat actors continue to adapt social engineering methods by combining trusted services, search results, and software impersonation techniques. Organizations and users are advised to verify software downloads through official sources, avoid executing unknown commands from websites, and maintain security controls to reduce exposure to malware campaigns using ClickFix-style tactics.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Post Comment