Find notable cyber news and cases, enriched with sources, timelines, and signals.

ChainScript RAT delivered via ClickFix-like lures

Malware Activity
First reported
Last updated
Happening score
H score 23
1 unique sources, 1 articles

Summary

Hide ▲

The ChainScript RAT is being delivered through ClickFix-like lures, giving operators remote access and payload deployment control on compromised Windows systems. The malware also supports screenshot capture, file operations, wallet enumeration, and remote JavaScript execution, expanding attacker control after infection. Its operators use an EtherHiding-style C2 discovery method tied to a Polygon smart contract to locate active WebSocket infrastructure. The combination of lure-based delivery, persistence, and rotating backend discovery makes the malware harder to detect and disrupt.

Related Happenings

PasteSwitch malicious ClickFix ads campaign via HBO Max Reddit account

Campaign
H score32 First: 21.09.2026 11:39 Last: 21.09.2026 11:39 Sources 1

How related: The disclosure comes as threat actors compromised HBO Max's official Reddit account ("u/hbomax") and abused it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware.

About this happening: The PasteSwitch campaign abused HBO Max's official Reddit account (u/hbomax) to push 108 malicious ads over 48 hours, turning a trusted brand channel into a delive...

UAC-0145 / Sandworm ClickFix campaign targeting Ukrainian targets

Campaign
H score24 First: 19.07.2026 16:30 Last: 19.07.2026 16:30 Sources 1

About this happening: A UAC-0145 / Sandworm campaign is using ClickFix fake CAPTCHA pages on compromised websites to push malware onto Ukrainian targets, widening infection risk across at l...

ClickLock ClickFix macOS targeting campaign

Campaign
H score33 First: 16.07.2026 15:33 Last: 16.07.2026 15:33 Sources 1

About this happening: Group-IB reported a ClickLock macOS campaign that uses ClickFix paste-a-command lures and coercive app-killing loops to force victims to enter their system login...

TonRAT Node.js implant with TON blockchain C2

Malware Activity
H score24 First: 26.06.2026 12:27 Last: 26.06.2026 12:27 Sources 1

About this happening: TonRAT is using a Node.js implant to hide command-and-control lookups behind the TON blockchain API, increasing the chance that blocking and detection will fail. The a...

KongTuke ClickFix and Teams access-seeking campaign

Campaign
H score33 First: 25.06.2026 11:54 Last: 25.06.2026 11:54 Sources 1

About this happening: The KongTuke/Woodgnat campaign now includes Node.js/node.exe abuse to run attacker JavaScript and deploy payloads in targeted attacks against government departments*...

Latest development: 03.09.2026 13:43

KongTuke/Woodgnat actors have abused the signed Node.js/node.exe runtime to run attacker JavaScript and deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels since February 2026. One intrusion against an unspecified Asian technology company between March 23 and July 25, 2026 used the official Node.js installer from nodejs[.]org and EtherHiding to establish long-term access, and related attack chains also involve CrashFix, ModeloRAT, Mistic, GateKeeper, C2Looper, and AsukaStealer.

Timeline

  1. 21.09.2026 11:39 2 articles · 1h ago

    ClickFix lures deliver the ChainScript RAT through a malicious Windows installer

    Initial Disclosure

    Researchers disclosed ChainScript, a previously undocumented remote access trojan, being delivered through ClickFix-like lures and a malicious Windows installer disguised as Spotify. The installer is launched with msiexec.exe, deploys the Node.js runtime, and uses hidden PowerShell and VBScript stages to start the ChainScript JavaScript agent; the malware then establishes user-level persistence through a scheduled task with a Registry Run key fallback and connects over WebSockets to Polygon smart-contract-resolved C2 infrastructure.

    Show sources