Threat Intelligence

New ChainScript Malware Uses ClickFix Scams and Blockchain Tricks to Stay Hidden

The Hacker News · 21 Sept 2026
Key Takeaway Train staff to be suspicious of unexpected prompts asking them to run commands or install software, since these ClickFix-style scams are a common way malware like ChainScript gets a foothold.

Security researchers at Blackpoint Adversary Pursuit Group have identified a new remote access trojan (RAT) named ChainScript, which is being distributed under disguises such as Spotify, Zoom Workplace, and Microsoft Teams installers. The malware is delivered through so-called ClickFix lures, deceptive prompts that trick users into running malicious commands, which then download a fake installer that quietly sets up the malware in the background.

Once installed, ChainScript gives attackers extensive remote control over a victim's computer. This includes running commands, stealing files, taking screenshots, deploying further malware, and searching for cryptocurrency wallets on the device or in browser extensions. To stay hidden and resilient, ChainScript uses a technique that looks up its control server address through a Polygon blockchain smart contract rather than a fixed web address, making it much harder for defenders to block or take down.

The malware also builds in persistence, meaning it can survive a restart by quietly re-launching itself through scheduled tasks or registry settings, and it can update or remove itself remotely. Researchers note this reflects a broader trend of cybercriminals using decentralised infrastructure to keep their operations running even when parts of it are disrupted.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.