#ChainScript
Threat actors use ClickFix-like lures to spread ChainScript, a new remote access Trojan masquerading as apps like Spotify, Zoom, and Teams. #CyberSecurity
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
ClickFix lures deliver the ChainScript RAT, which uses a Polygon smart contract to locate active WebSocket command-and-control servers.
thehackernews.com
September 22, 2026 at 3:33 PM
New ChainScript RAT using blockchain-based C2 rotation exploits ClickFix lures—researchers uncover novel delivery technique targeting enterprise users through spoofed software…

https://thehackernews.com/2026/09/clickfix-lures-deploy-chainscript-rat.html

#cybersecurity #infosec
September 22, 2026 at 2:30 PM
ChainScript: the RAT that hides its command server inside a blockchain contract

Blackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server. Blackpoint’s Adversary Pursuit Group was chasing a ClickFix campaign spreadi…
#hackernews #news
ChainScript: the RAT that hides its command server inside a blockchain contract
Blackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server. Blackpoint’s Adversary Pursuit Group was chasing a ClickFix campaign spreading an unknown RAT namend ChainScript. The malicious code is a previously undocumented Node.js remote access trojan that hides its command server on a public blockchain. The […]
securityaffairs.com
September 22, 2026 at 11:24 AM
ClickFix Attacks Spread ChainScript RAT via Fake Spotify and Teams Installers

Blackpoint Cyber found ChainScript, a Node.js RAT spread through fake Spotify, Zoom and Teams installers that uses Polygon smart contracts to locate its C2 server.
#hackernews #news
ClickFix Attacks Spread ChainScript RAT via Fake Spotify and Teams Installers
Blackpoint Cyber found ChainScript, a Node.js RAT spread through fake Spotify, Zoom and Teams installers that uses Polygon smart contracts to locate its C2 server.
hackread.com
September 22, 2026 at 8:20 AM
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript.

"ChainScript has appeared under multiple build names, i…
#hackernews #microsoft #news
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript. "ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while presenting itself as Spotify, Zoom Workplace, and Microsoft Teams software," Blackpoint Adversary Pursuit Group (APG)
thehackernews.com
September 22, 2026 at 4:56 AM
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
September 21, 2026 at 11:59 PM
🖲️ #Noticia #CiberSeguridad #Cybersecurity #CiberNoticia

ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

Leer Más / Read More...
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Haz clic para acceder al contenido completo.
thehackernews.com
September 21, 2026 at 2:29 PM
Blackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server. Blackpoint’s Adversary Pursuit Group was chasing a ClickFix campaign spreading an unknown RAT namend ChainScript. The malicious code is a previously undocumented Node.js […]
Original post on poliverso.org
poliverso.org
September 21, 2026 at 2:24 PM
ClickFix Luresが、Polygonを利用してC2インフラをローテーションするChainScript RATを配信。Spotify, Zoom, Teamsを偽装。
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
ClickFix lures deliver the ChainScript RAT, which uses a Polygon smart contract to locate active WebSocket command-and-control servers.
thehackernews.com
September 21, 2026 at 12:37 PM
🤖 New RAT "ChainScript" delivered via ClickFix-style lures, posing as Spotify, Zoom Workplace and Microsoft Teams. C2 infrastructure rotated through Polygon smart contracts to evade takedowns. (Blackpoint APG)
https://thehackernews.com/2026/09/clickfix-lures-deploy-chainscript-rat.html
September 21, 2026 at 12:25 PM
Fake Spotify, Zoom and Teams installers are being used in ClickFix attacks to spread ChainScript, a Node.js RAT that uses Polygon smart contracts to locate its C2 server.

Listen/Read: hackread.com/clickfix-cha...

#Cybersecurity #Malware #ClickFix #ChainScript #NodeJS #Polygon
ClickFix Attacks Spread ChainScript RAT via Fake Spotify and Teams Installers
Blackpoint Cyber found ChainScript, a Node.js RAT spread through fake Spotify, Zoom and Teams installers that uses Polygon smart contracts to locate its C2 server.
hackread.com
September 21, 2026 at 11:38 AM
Threat actors are deploying a new remote access trojan called ChainScript via ClickFix lures, using a Polygon smart contract for […]
New ChainScript RAT uses blockchain-based C2 via ClickFix lures
Threat actors are deploying a new remote access trojan called ChainScript via ClickFix lures, using a Polygon smart contract for […]
bitnewsbot.com
September 21, 2026 at 11:34 AM
September 21, 2026 at 9:03 AM
ClickFix詐欺がChainScript RATを配布、Polygonで C2インフラを動的管理

ClickFix詐欺キャンペーンがChainScript RATマルウェアを配布。Polygonブロックチェーンのスマートコントラクトを悪用してC2サーバーを動的に切り替え、検出回避を実現。Windows ユーザーが主な対象。

#マルウェア #標的型攻撃 #情報セキュリティ
ClickFix詐欺がChainScript RATを配布、Polygonで C2インフラを動的管理
ClickFix詐欺キャンペーンがChainScript RATマルウェアを配布。Polygonブロックチェーンのスマートコントラクトを悪用してC2サーバーを動的に切り替え、検出回避を実現。Windows ユーザーが主な対象。
thehackernews.com
September 21, 2026 at 9:01 AM
ChainScript is a ClickFix-delivered RAT that uses Polygon smart-contract C2 discovery and provides full remote control, persistence, and self-update capabilities.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 21, 2026 at 8:52 AM
ChainScript is a ClickFix-delivered RAT that uses Polygon smart-contract C2 discovery and provides full remote control, persistence, and self-update capabilities.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 21, 2026 at 8:52 AM
ChainScript is a ClickFix-delivered RAT that uses Polygon smart-contract C2 discovery and provides full remote control, persistence, and self-update capabilities.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
September 21, 2026 at 8:51 AM
ClickFix Lures ChainScript RAT on Polygon to Rotate C2

What is ChainScript RAT? ChainScript is a remote access trojan that first appeared in late 2023.

https://bloggersminds.com/post/clickfix-lures-chainscript-rat-on-polygon-to-rotate-c2-6283
ClickFix Lures ChainScript RAT on Polygon to Rotate C2
What is ChainScript RAT? ChainScript is a remote access trojan that first appeared in late 2023.
bloggersminds.com
September 21, 2026 at 8:48 AM
📢 ChainScript : un RAT Node.js utilisant la blockchain Polygon pour sa découverte C2

Cet article présente l'analyse technique complète d'un RAT Node.js jusqu'alors non documenté, désormais suivi sous le nom ChainScript. La…

🟢 vérification factuelle haute
#ChainScript #ClickFix #Cyberveille
ChainScript : un RAT Node.js utilisant la blockchain Polygon pour sa découverte C2
Cet article présente l'analyse technique complète d'un RAT Node.js jusqu'alors non documenté, désormais suivi sous le nom ChainScript. La découverte a eu lieu lors d'une investigation sur une campagne ClickFix.
cyberveille.ch
September 21, 2026 at 12:30 AM