Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

ChainScript: A Sophisticated RAT Malware Leveraging ClickFix-Like Lures and Polygon-Based C2 Infrastructure


ChainScript, a sophisticated RAT malware, has been discovered, leveraging ClickFix-like lures and Polygon-based C2 infrastructure to deliver a full-featured remote access trojan. The malware has infected Windows and macOS devices, with malicious ads being served on compromised HBO Max Reddit accounts. The attack represents a new pattern of malware using development frameworks and blockchain-based C2 discovery to enable infrastructure rotation and complicate traditional indicator-based detection.

  • ChainScript, a sophisticated remote access trojan (RAT) malware, has been deployed via ClickFix-like lures, making it challenging to detect and mitigate.
  • The malware uses an EtherHiding-style command-and-control (C2) discovery technique, utilizing a Polygon smart contract to locate its active WebSocket infrastructure.
  • ChainScript provides extensive remote access to the operator, including interactive CMD and PowerShell, file operations, and cryptocurrency wallet enumeration.
  • Threat actors have compromised HBO Max's official Reddit account to push malicious ads that launched ClickFix attacks to infect devices with information-stealing malware.
  • The malware, known as MacSync, has primarily targeted regions with widespread macOS enterprise use, tech, and software development sectors, and active cryptocurrency or Web3 communities.
  • The threat actors used highly polished assets to establish trust before delivering the malicious payload, bypassing initial skepticism from users.



  • The cyber threat landscape has witnessed a recent surge in the deployment of remote access trojan (RAT) malware, with one particularly sophisticated variant, ChainScript, making headlines in the threat intelligence community. According to recent reports, threat actors have been leveraging ClickFix-like lures to deliver the previously undocumented RAT, dubbed ChainScript.

    ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while presenting itself as Spotify, Zoom Workplace, and Microsoft Teams software. The malware employs an EtherHiding-style command-and-control (C2) discovery technique, utilizing a Polygon smart contract to locate its active WebSocket infrastructure. This innovative approach allows the threat actor to rotate their C2 infrastructure, making it increasingly difficult to detect and mitigate the malware.

    The full-featured RAT, ChainScript, provides extensive remote access to the operator, including interactive CMD and PowerShell, file operations, screenshot capture, payload deployment, cryptocurrency wallet enumeration (both desktop apps and browser extensions), and remote JavaScript execution. The starting point of the attack chain is a ClickFix lure that leads to the download and execution of a malicious Windows installer using "msiexec.exe." The installer, disguised as Spotify, deploys the Node.js runtime and launches the ChainScript JavaScript agent through hidden PowerShell and VBScript stages.

    The running agent then establishes user-level persistence through a scheduled task with a Registry Run key fallback. Upon execution, ChainScript connects to the C2 server over WebSockets and retrieves additional tasking, giving the threat actor direct control over the compromised system. The supported commands also allow it to self-update and remove persistence.

    The findings illustrate how threat actors are increasingly adopting a flexible decentralized infrastructure as a way to resist takedown efforts and ensure uninterrupted operations. ChainScript reflects an emerging pattern of malware using development frameworks and blockchain-based C2 discovery to enable infrastructure rotation and complicate traditional indicator-based detection.

    Moreover, the disclosure comes as threat actors compromised HBO Max's official Reddit account ("u/hbomax") and abused it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. The activity has been codenamed PasteSwitch by Hudson Rock and ADAMnetworks. It's not known how the account was breached, and how many people clicked on these fake ads and how many were compromised as a result.

    On macOS, PasteSwitch has been found to deliver MacSync, Atomic macOS Stealer (AMOS), and fake cryptocurrency wallet applications designed to steal recovery phrases. The Windows branch, on the other hand, distributes Amatera Stealer and cryptocurrency clippers like AnimateClipper and ZigClipper. In all, the verified Reddit account served 108 malicious ads over a 48-hour period in mid-September 2026.

    According to data shared by Seqrite Labs, MacSync infections have concentrated in the U.S., followed by the U.K., Germany, Japan, Canada, France, Singapore, Australia, India, and the Netherlands. "MacSync campaigns primarily target regions with widespread macOS enterprise use, tech and software development sectors, and active cryptocurrency or Web3 communities," researcher Chandra Kant Bauri said.

    "The threat actors utilized highly polished assets to establish trust before delivering the malicious payload," Hudson Rock said. "By hijacking a verified corporate account, they bypassed the initial skepticism many users apply to internet advertisements."

    The findings dovetail with another ClickFix campaign that employs a fake Codex download experience surfaced via search results to lead users to bogus Google Sites pages and trick macOS users into pasting a malicious command into Terminal, resulting in the execution of Atomic Stealer. Visitors using non-Mac devices are served a harmless decoy page.

    "The copied Terminal command first retrieves a shell-script loader: the first stage," Cato Networks said. "This loader contains an embedded blob that it decodes and executes with eval, producing the second-stage shell script. The second stage then records execution and retrieves the final, third-stage Mach-O payload."

    The cybersecurity company described the activity as part of a broader pattern of attacks that employ trusted services and large language model (LLM) shared chats to serve fake installation instructions, while bypassing browser warnings, URL inspection, and Safe Browsing heuristics.

    In a report published last month, Microsoft said it observed a macOS ClickFix campaign propagating MacSync and Atomic Stealer using a cluster of no less than 250 look-alike domains.

    "The campaign evolved from broadly serving ClickFix lures to using a server-side browser-fingerprinting gate that shows the lure primarily to visitors whose environment appears consistent with a genuine macOS browser," it said. "This cloaking limits visibility for crawlers, sandboxes, and some automated analysis workflows."



    Related Information:
  • https://www.ethicalhackingnews.com/articles/ChainScript-A-Sophisticated-RAT-Malware-Leveraging-ClickFix-Like-Lures-and-Polygon-Based-C2-Infrastructure-ehn.shtml

  • https://thehackernews.com/2026/09/clickfix-lures-deploy-chainscript-rat.html


  • Published: Mon Sep 21 03:57:08 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us