Threats & Adversaries · Credential Theft

ChainScript Hides C2 Behind Polygon Lookups

Blackpoint Adversary Pursuit Group identified ChainScript, a previously undocumented RAT spread with ClickFix-style lures that pose as Spotify, Zoom Workplace, and Microsoft Teams installers. The malware uses a Polygon smart contract to find its current WebSocket command server, letting the operator move infrastructure without changing the implant.

The infection chain starts with a fake installer that runs through msiexec.exe, drops a Node.js-based agent, and then uses hidden PowerShell and VBScript stages to launch the payload. Once running, ChainScript can open a remote shell, move files, take screenshots, enumerate crypto wallets, and deploy more code, while the C2 location keeps shifting behind the blockchain lookup.

That leaves defenders chasing a moving backend instead of a fixed server list. If users in an organization can be fooled into running lookalike collaboration-app installers, the delivery lure and the decentralized C2 model both sit inside the same exposure, and blocklists alone will not catch the live control point.

1 source · 15h ago

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-09-21

Every edition of this story: ChainScript Hides C2 Behind Polygon Lookups

More from today