New ChainScript Malware Uses ClickFix Scams and Blockchain Tricks to Stay Hidden
Security researchers at Blackpoint Adversary Pursuit Group have identified a new remote access trojan (RAT) named ChainScript, which is being distributed under disguises such as Spotify, Zoom Workplace, and Microsoft Teams installers. The malware is delivered through so-called ClickFix lures, deceptive prompts that trick users into running malicious commands, which then download a fake installer that quietly sets up the malware in the background.
Once installed, ChainScript gives attackers extensive remote control over a victim's computer. This includes running commands, stealing files, taking screenshots, deploying further malware, and searching for cryptocurrency wallets on the device or in browser extensions. To stay hidden and resilient, ChainScript uses a technique that looks up its control server address through a Polygon blockchain smart contract rather than a fixed web address, making it much harder for defenders to block or take down.
The malware also builds in persistence, meaning it can survive a restart by quietly re-launching itself through scheduled tasks or registry settings, and it can update or remove itself remotely. Researchers note this reflects a broader trend of cybercriminals using decentralised infrastructure to keep their operations running even when parts of it are disrupted.