Threat actors are deploying a previously undocumented remote access trojan (RAT) called ChainScript through ClickFix-style social engineering attacks. The malware uses blockchain technology to rotate command-and-control infrastructure, complicating detection and takedown efforts.
Blackpoint Adversary Pursuit Group (APG) identified the RAT operating under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66. The malware masquerades as legitimate software such as Spotify, Zoom Workplace, and Microsoft Teams during delivery and installation phases.
The ClickFix attack vector remains deceptively simple. Victims encounter fake error messages or browser notifications prompting them to fix critical system issues. Clicking these fake alerts redirects users to malicious pages hosting ChainScript payloads. This technique exploits human psychology and user trust in legitimate software vendors, making it effective across both technical and non-technical targets.
ChainScript's use of Polygon blockchain technology for C2 rotation represents an evolution in adversary tradecraft. Rather than relying on traditional DNS records or IP-based infrastructure, threat actors hardcode blockchain addresses into the malware. The RAT queries Polygon smart contracts to retrieve updated command-and-control server addresses. This approach complicates takedown operations because blockchain infrastructure remains decentralized and censorship-resistant. Law enforcement and security vendors cannot simply seize domain names or IP ranges to disrupt operations.
The payload delivers standard RAT capabilities including remote desktop access, keylogging, screen capture, and credential harvesting. Once installed, ChainScript establishes persistence mechanisms to survive system reboots and maintain long-term access to compromised machines.
Organizations face elevated risk from this variant because ClickFix attacks require minimal technical sophistication from the attacker side while achieving high social engineering success rates. Users across all experience levels remain vulnerable to convincing fake error notifications. The rebranding under multiple software vendors and build names suggests a campaigns-as-a-service operation where different threat groups or resellers distribute the same malware payload under different names.
The blockchain-based C2 infrastructure indicates sophistication in operational security. Threat actors can rotate infrastructure without disrupting command delivery to existing compromised systems. They avoid creating new domains, registrar records, or IP assignments that trigger security monitoring alerts. This approach reduces the malware's attribution surface and extends its operational lifespan.
Mitigation requires user awareness training focused on identifying fake system alerts and verifying software downloads through official vendor channels only. Organizations should disable browser notifications from untrusted websites and implement application whitelisting controls. Endpoint detection and response (EDR) solutions should monitor for ChainScript's persistence mechanisms and blockchain DNS queries, which deviate from normal network traffic patterns.
Network defenders analyzing ChainScript samples should monitor for connections to Polygon blockchain infrastructure and suspicious parent-child process relationships between browsers and system utilities. The multiple build names mean organizations cannot rely solely on hash-based detection. Behavior-based detection focusing on keylogging and credential access activities provides more reliable coverage across ChainScript variants.
