ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
News Source : Internet
News Summary
- Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript.
- ChainScript employs an EtherHiding -style command-and-control (C2) discovery technique that makes use of a Polygon smart contract to locate its active WebSocket infrastructure.
- The disclosure comes as threat actors compromised HBO Max's official Reddit account and abused it to push malicious ads that launched ClickFix attacks to infect Windows and Mac devices with information-stealing malware.
Threat actors are leveraging ClickFixlike lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript.
Never miss a story from us, subscribe to our newsletter