Securityaffairs ChainScript RAT Uses Blockchain for C2 Infrastructure Rotation
Article Content
- •ChainScript RAT disguises itself as legitimate applications like Spotify.
- •The malware uses a Polygon smart contract for dynamic command-and-control server discovery.
- •ChainScript can perform extensive remote operations, including file access and cryptocurrency wallet enumeration.
Blackpoint has identified a new remote access trojan (RAT) named ChainScript, which employs ClickFix lures to infect users. The malware disguises itself as legitimate software like Spotify and uses msiexec.exe to execute a malicious installer. ChainScript operates as a Node.js RAT, utilizing a Polygon smart contract for command-and-control (C2) server discovery through a technique called EtherHiding. This allows the malware to rotate its C2 infrastructure easily, complicating detection efforts. The malware is capable of extensive remote operations, including file manipulation and cryptocurrency wallet enumeration. The attack vector primarily targets Windows systems, and the malware has been observed to establish user-level persistence. Blackpoint's Adversary Pursuit Group has been monitoring the activity and noted the malware's ability to update itself and maintain a connection to the C2 server. As of now, the threat remains active and poses a significant risk to affected users.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track ClickFix and HBO Max in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Russia's AI-Driven Cyber Espionage Targets Ukraine and Europe A Russian-linked hacking group, identified as GTG-20006, has utilized Anthropic's Claude AI to automate cyber espionage against over 20 organizations, primarily in Ukraine and Europe. The group targeted Ukrainian government officials, military personnel, and drone manufacturers through sophisticated phishing and…
Healthcare Cyberattacks Disrupt Patient Care and Expose Sensitive Data Two major healthcare companies, Boston Scientific and Nutex Health, reported cyberattacks that compromised patient data and disrupted operations. Boston Scientific's systems were breached on August 25, affecting the functionality of pacemakers and other heart devices, preventing remote monitoring. The company is…