ClickFix Lures Deploy ChainScript RAT via Polygon C2 Rotation
Blackpoint researchers uncovered a new RAT called ChainScript delivered through ClickFix-style lures posing as Spotify, Zoom Workplace and Microsoft Teams. The malware uses the Polygon blockchain to rotate its command-and-control infrastructure.
- ChainScript RAT spreads via ClickFix-style lures
- Malware masquerades as Spotify, Zoom and Microsoft Teams
- Polygon blockchain used to rotate C2 infrastructure
- Known builds include ComponentTask33, UpdateDigital, HostShared, OrchidViolet66
Read next
Security