EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
← Torna all'intelligence
Avviso tecnico

ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

Fonte editoriale
Fonte OSINT editoriale. Il contenuto e un'indicazione da verificare con fonti istituzionali o tecniche indipendenti prima di decisioni operative.
Sintesi operativa EudorIA

Cosa significa

Priorità 85/100

Threat actors use ClickFix lures to deploy ChainScript RAT, a previously undocumented remote access trojan. The malware disguises itself as legitimate software and uses a Polygon smart contract to rotate C2 infrastructure. The attack chain starts with a malicious Windows installer that executes via msiexec.exe, deploying the RAT through hidden PowerShell and VBScript stages. The malware provides extensive remote access and can self-update and remove persistence. The threat actors also compromised HBO Max's Reddit account to push malicious ads, leading to infections on Windows and macOS devices with various stealers.

Perché conta

For Italian PMIs, this represents a significant risk as ChainScript can grant attackers full control over systems, leading to data theft, financial loss, and operational disruption. The use of decentralized infrastructure and social engineering via trusted accounts like Reddit makes detection and mitigation more challenging.

Benefici operativi potenziali

  • Reduces the risk of malware deployment through ClickFix lures.
  • Enhances detection and response capabilities against ChainScript RAT.
  • Improves overall system resilience against advanced persistent threats.
  • Strengthens user authentication and access control mechanisms.
Indicazioni da confermare sul perimetro tecnico e organizzativo del cliente.
Controlli pertinentiFirewall NGFW / IPSEDR / XDRMFA / IdentitàPatch managementSegmentazione di rete
DestinatariITSOCCISO
Centro informazioni

Traduzione in elaborazione

The Hacker News

Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.

Testo acquisito dalla fonte

Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript. "ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while presenting itself as Spotify, Zoom Workplace, and Microsoft Teams software," Blackpoint Adversary Pursuit Group (APG)

Fonte
The Hacker News
Entità pubblicatrice
The Hacker News
Tipo entità
editorial osint
Area
Global
Lingua originale
en · traduzione in preparazione
Pubblicazione
21/09/2026 10:39
MITRE ATT&CK
T1190, T1078, T1486
Apri la fonte originale