Skip to content
ChainScript RAT Uses Blockchain for C2 Infrastructure Rotation

ChainScript RAT Uses Blockchain for C2 Infrastructure Rotation

First seen 21 Sep 2026, 14:51 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 21, 2026 at 16:21 UTC
  • ChainScript RAT disguises itself as legitimate applications like Spotify.
  • The malware uses a Polygon smart contract for dynamic command-and-control server discovery.
  • ChainScript can perform extensive remote operations, including file access and cryptocurrency wallet enumeration.

Blackpoint has identified a new remote access trojan (RAT) named ChainScript, which employs ClickFix lures to infect users. The malware disguises itself as legitimate software like Spotify and uses msiexec.exe to execute a malicious installer. ChainScript operates as a Node.js RAT, utilizing a Polygon smart contract for command-and-control (C2) server discovery through a technique called EtherHiding. This allows the malware to rotate its C2 infrastructure easily, complicating detection efforts. The malware is capable of extensive remote operations, including file manipulation and cryptocurrency wallet enumeration. The attack vector primarily targets Windows systems, and the malware has been observed to establish user-level persistence. Blackpoint's Adversary Pursuit Group has been monitoring the activity and noted the malware's ability to update itself and maintain a connection to the C2 server. As of now, the threat remains active and poses a significant risk to affected users.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-21
Blackpoint uncovers ChainScript RAT
Researchers identified ChainScript, a Node.js RAT that uses ClickFix lures and blockchain for C2 discovery.
Securityaffairs
2026-09-21
ChainScript deployment reported
Threat actors are using ClickFix-like lures to deliver ChainScript, which has multiple build names and disguises.
Thehackernews

More articles in this cluster (3)

Following this threat?

Track ClickFix and HBO Max in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed