ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

**ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure**

A sophisticated cyber attack campaign has been uncovered, leveraging a novel combination of social engineering and malware deployment techniques to infect unsuspecting users. The attackers are using a tool called ClickFix, which poses as a legitimate software update, but in reality, it’s a trojan horse designed to install the ChainScript Remote Access Trojan (RAT). The RAT’s command and control (C2) infrastructure is being rotated using Polygon, a decentralized network protocol that enables the creation of a robust communication channel between the attacker’s servers and compromised devices.

The campaign has already affected numerous individuals and organizations worldwide, with the attackers targeting users who have fallen victim to phishing scams or exploited vulnerabilities in their software. Once installed, ChainScript RAT grants the attackers remote access to the compromised device, allowing them to steal sensitive data, install additional malware, or even take control of the device’s system functions.

To carry out this attack, the ClickFix tool is designed to evade detection by security software, using advanced techniques such as code obfuscation and sandbox evasion. Once installed, it establishes a connection with the attacker’s C2 server, which is dynamically rotated using Polygon. This approach makes it increasingly difficult for security researchers and incident responders to pinpoint the source of the attack and track down the compromised devices.

The ChainScript RAT itself is a modular malware framework that allows attackers to customize their attacks and adapt to changing circumstances on the fly. The malware’s capabilities include data exfiltration, keystroke logging, and system modification, making it a versatile tool for conducting reconnaissance, espionage, or even destructive operations.

This campaign highlights the ongoing cat-and-mouse game between cyber attackers and defenders. As security measures become more sophisticated, attackers are forced to innovate and adapt their tactics, often using novel combinations of social engineering, malware, and communication protocols. The use of Polygon in this case is particularly noteworthy, as it demonstrates the increasing trend towards decentralized and dynamic C2 infrastructure.

In light of this attack campaign, users should exercise extreme caution when receiving unsolicited software updates or notifications that prompt them to download unknown files. It’s essential to ensure that all software and plugins are up-to-date with the latest security patches, and to maintain a robust security posture through regular backups, system monitoring, and timely incident response planning.


Source: The Hacker News — 2026-09-21