ChainScript RAT delivered via ClickFix-like lures
Malware Activity
Summary
Hide ▲
Show ▼
The ChainScript RAT is being delivered through ClickFix-like lures, giving operators remote access and payload deployment control on compromised Windows systems. The malware also supports screenshot capture, file operations, wallet enumeration, and remote JavaScript execution, expanding attacker control after infection. Its operators use an EtherHiding-style C2 discovery method tied to a Polygon smart contract to locate active WebSocket infrastructure. The combination of lure-based delivery, persistence, and rotating backend discovery makes the malware harder to detect and disrupt.
Related Happenings
PasteSwitch malicious ClickFix ads campaign via HBO Max Reddit account
Campaign
H score32
First: 21.09.2026 11:39
Last: 21.09.2026 11:39
Sources 1
How related:
The disclosure comes as threat actors compromised HBO Max's official Reddit account ("u/hbomax") and abused it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware.
About this happening:
The PasteSwitch campaign abused HBO Max's official Reddit account (u/hbomax) to push 108 malicious ads over 48 hours, turning a trusted brand channel into a delive...
PasteSwitch malicious ClickFix ads campaign via HBO Max Reddit account
CampaignHow related: The disclosure comes as threat actors compromised HBO Max's official Reddit account ("u/hbomax") and abused it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware.
About this happening: The PasteSwitch campaign abused HBO Max's official Reddit account (u/hbomax) to push 108 malicious ads over 48 hours, turning a trusted brand channel into a delive...
UAC-0145 / Sandworm ClickFix campaign targeting Ukrainian targets
Campaign
H score24
First: 19.07.2026 16:30
Last: 19.07.2026 16:30
Sources 1
About this happening:
A UAC-0145 / Sandworm campaign is using ClickFix fake CAPTCHA pages on compromised websites to push malware onto Ukrainian targets, widening infection risk across at l...
UAC-0145 / Sandworm ClickFix campaign targeting Ukrainian targets
CampaignAbout this happening: A UAC-0145 / Sandworm campaign is using ClickFix fake CAPTCHA pages on compromised websites to push malware onto Ukrainian targets, widening infection risk across at l...
ClickLock ClickFix macOS targeting campaign
Campaign
H score33
First: 16.07.2026 15:33
Last: 16.07.2026 15:33
Sources 1
About this happening:
Group-IB reported a ClickLock macOS campaign that uses ClickFix paste-a-command lures and coercive app-killing loops to force victims to enter their system login...
ClickLock ClickFix macOS targeting campaign
CampaignAbout this happening: Group-IB reported a ClickLock macOS campaign that uses ClickFix paste-a-command lures and coercive app-killing loops to force victims to enter their system login...
TonRAT Node.js implant with TON blockchain C2
Malware Activity
H score24
First: 26.06.2026 12:27
Last: 26.06.2026 12:27
Sources 1
About this happening:
TonRAT is using a Node.js implant to hide command-and-control lookups behind the TON blockchain API, increasing the chance that blocking and detection will fail. The a...
TonRAT Node.js implant with TON blockchain C2
Malware ActivityAbout this happening: TonRAT is using a Node.js implant to hide command-and-control lookups behind the TON blockchain API, increasing the chance that blocking and detection will fail. The a...
KongTuke ClickFix and Teams access-seeking campaign
Campaign
H score33
First: 25.06.2026 11:54
Last: 25.06.2026 11:54
Sources 1
About this happening:
The KongTuke/Woodgnat campaign now includes Node.js/node.exe abuse to run attacker JavaScript and deploy payloads in targeted attacks against government departments*...
KongTuke ClickFix and Teams access-seeking campaign
CampaignAbout this happening: The KongTuke/Woodgnat campaign now includes Node.js/node.exe abuse to run attacker JavaScript and deploy payloads in targeted attacks against government departments*...
Latest development: 03.09.2026 13:43
KongTuke/Woodgnat actors have abused the signed Node.js/node.exe runtime to run attacker JavaScript and deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels since February 2026. One intrusion against an unspecified Asian technology company between March 23 and July 25, 2026 used the official Node.js installer from nodejs[.]org and EtherHiding to establish long-term access, and related attack chains also involve CrashFix, ModeloRAT, Mistic, GateKeeper, C2Looper, and AsukaStealer.
Timeline
-
21.09.2026 11:39 2 articles · 12h ago
ClickFix lures deliver the ChainScript RAT through a malicious Windows installer
Initial DisclosureResearchers disclosed ChainScript, a previously undocumented remote access trojan, being delivered through ClickFix-like lures and a malicious Windows installer disguised as Spotify. The installer is launched with msiexec.exe, deploys the Node.js runtime, and uses hidden PowerShell and VBScript stages to start the ChainScript JavaScript agent; the malware then establishes user-level persistence through a scheduled task with a Registry Run key fallback and connects over WebSockets to Polygon smart-contract-resolved C2 infrastructure.
Show sources
- ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure — thehackernews.com — 21.09.2026 11:39
- ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure — thehackernews.com — 21.09.2026 11:39