ClickFix Attacks Spread ChainScript RAT via Fake Spotify and Teams Installers
Cybersecurity researchers at Blackpoint Cyber have identified a Node.js remote access trojan (RAT) called ChainScript while investigating a ClickFix campaign that used a fake Spotify installer to infect Windows users.
The company’s Adversary Pursuit Group (APG) found that ChainScript gives attackers remote control of infected systems and uses a Polygon smart contract to locate its command-and-control (C2) server.
ClickFix Delivers the ChainScript RAT
The research, shared with Hackread.com, reveals that the attack starts with ClickFix instructions that persuade a victim to run a command through Windows tools. The command uses msiexec.exe to retrieve ComponentTask33-4d14e6ac.msi from attacker-controlled infrastructure.
The MSI presents itself as Spotify software and launches hidden PowerShell and VBScript stages that install a bundled Node.js runtime and the ChainScript agent.
ChainScript establishes persistence through a scheduled task named ComponentTask33Agent, with a Windows Run key used as a fallback. Once running, the RAT gives attackers broad control of the...
Copyright of this story solely belongs to hackread.com. To see the full text click HERE