Security researchers have documented a new remote access trojan (RAT) named ChainScript that is being distributed through ClickFix-style lures, a social engineering technique that tricks victims into manually executing malicious commands under the guise of fixing a technical problem.

According to Blackpoint’s Adversary Pursuit Group (APG), the malware has surfaced under several different build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66. In each case, the payload masquerades as legitimate, widely used software to lower victims’ guard.

Impersonating Trusted Applications

ChainScript has been observed disguising itself as popular collaboration and media tools, specifically Spotify, Zoom Workplace, and Microsoft Teams. By mimicking these well-known applications, the malware increases the likelihood that a target will trust and execute the malicious file when prompted through a ClickFix lure.

Rotating Infrastructure via Polygon

A notable feature of the ChainScript campaign is its use of the Polygon blockchain network to rotate command-and-control (C2) infrastructure. Leveraging a public blockchain for C2 resilience allows operators to update or relocate infrastructure in a way that is harder to disrupt through traditional takedown methods, since blockchain-based data is decentralized and not tied to a single hosting provider.

Why It Matters

ClickFix-based delivery has become an increasingly common initial access vector because it relies on user interaction rather than exploiting a software vulnerability, making it effective against environments with strong patch management but weaker user awareness training. The emergence of ChainScript under multiple build names and its use of blockchain-based C2 rotation suggests the operators behind it are actively iterating on both delivery and infrastructure resilience to evade detection and takedown efforts.

Security teams should be alert to ClickFix-style prompts asking users to run commands to resolve a supposed technical issue, and should treat unsolicited installers or updates for Spotify, Zoom Workplace, or Microsoft Teams with caution, especially when delivered outside official channels. Monitoring for unusual outbound connections tied to blockchain network queries may also help flag ChainScript-related activity.