ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
8 Articles
8 Articles
The attackers are using methods similar to ClickFix to provide an undocumented remote access virus (RAT) called ChainScrip. ClickFix is used to spread the ChainScrip RT virus using Polygon to rotate the C2 structure. The attackers are using similar methods to CickFix to deliver an undocumented remote access virus (RAT) called ChainScrip.
Blackpoint documents ChainScript, a blockchain malware written in Node.js that hides its command server in a smart Polygon contract. The entry Blackpoint detects ChainScript, the blockchain malware that hides its command in Polygon aparece primero en Moncloa.
Find out how the new ChainScript RAT uses smart contracts on the Polygon network and ClickFix baits to steal data and infect Windows and Mac.
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript. "ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while presenting itself as Spotify, Zoom Workplace, and Microsoft Teams software," Blackpoint Adversary Pursuit Group (APG)
Coverage Details
Bias Distribution
- 100% of the sources lean Right
Factuality
To view factuality data please Upgrade to Premium









