ChainScript RAT Leverages Blockchain to Evade Detection
Cybersecurity researchers have discovered a new Remote Access Trojan (RAT) called ChainScript, which uses ClickFix techniques to trick victims into gaining full access to their systems. The malware is notable for using blockchain infrastructure - specifically the Polygon network - to dynamically locate command and control (C2) servers, making it extremely difficult for traditional security solutions to counter.
The discovery of ChainScript RAT by the Blackpoint Adversary Pursuit Group indicates an increasing sophistication in modern cyberthreats. The malware has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, and presents itself as legitimate software for well-known applications such as Spotify, Zoom Workplace, and Microsoft Teams.
The use of EtherHiding for command-and-control (C2) by ChainScript RAT is particularly dangerous. The malware uses a Polygon smart contract to detect its active WebSocket infrastructure, allowing attackers to change C2 servers without modifying the malware itself. This approach renders traditional detection methods based on indicators of compromise ineffective.