ChainScript RAT Delivered via ClickFix Lures Rotates C2 on Polygon Network
What Happened — Threat actors are using “ClickFix”‑style phishing lures to drop a previously undocumented remote‑access trojan (RAT) named ChainScript. The payload masquerades as legitimate software such as Spotify, Zoom Workplace, and Microsoft Teams, and it leverages the Polygon network to rotate its command‑and‑control (C2) infrastructure.
Why It Matters for Trust & Control Assurance
- This scenario exemplifies the type of social‑engineering attack that a continuous security‑awareness program is designed to detect, document, and remediate.
- Demonstrates the need for auditable evidence that users receive timely training, that phishing simulations are logged, and that policy violations are escalated to incident‑response teams.
- Aligns with Verisq’s Security Awareness capability, which provides continuous monitoring of training completion, phishing test results, and proof of a defensible awareness posture.
Who Is Affected — Enterprises that rely on collaboration tools (e.g., Zoom, Microsoft Teams), SaaS platforms, and remote‑work environments across technology, finance, and professional services sectors.
Recommended Actions
- Refresh phishing‑simulation campaigns to include “ClickFix”‑style lures and RAT‑related indicators.
- Enforce application whitelisting and binary‑execution controls for all endpoints.
- Capture and retain evidence of user‑click events, training completion, and policy enforcement for audit readiness.
Technical Notes — ChainScript appears under build names like ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66. It uses the Polygon blockchain network to dynamically resolve C2 domains, complicating traditional blacklist approaches. Source: [The Hacker News]