Cybercriminals are deploying a new remote access trojan (RAT) known as ChainScript using ClickFix-style lures, according to a report by the Blackpoint Adversary Pursuit Group (APG). The malware utilizes the Polygon blockchain to rotate its command-and-control (C2) infrastructure, a tactic designed to increase the resilience of the attack against detection and takedown efforts.
The threat actors disguise the malicious payloads to appear as legitimate productivity and communication applications. According to Blackpoint, the malware presents itself to users as software from Spotify, Zoom Workplace, and Microsoft Teams, exploiting the familiarity of these brands to lower victim suspicion.
"ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while presenting itself as Spotify, Zoom Workplace, and Microsoft Teams software," Blackpoint Adversary Pursuit Group (APG) stated.
The use of ClickFix lures involves social engineering techniques where victims are tricked into executing malicious commands, often through manipulated browser console inputs or fake error messages. By leveraging these lures, attackers can bypass traditional security controls that rely on file-based signatures or automated execution prevention.
The integration of Polygon for C2 rotation represents a sophisticated evolution in threat actor infrastructure. By distributing C2 endpoints across a decentralized network, the attackers make it significantly more difficult for defenders to identify and block the communication channels used to control the compromised systems.
Security experts advise organizations to remain vigilant against social engineering attacks that mimic popular software updates or login prompts. Users should be trained to verify the authenticity of software installations and to avoid executing commands in browser consoles from untrusted sources, particularly when prompted by unexpected error dialogs.
<small>Source: The Hacker News — read the original story there.</small>