The record
Written from the 1 report below. Nothing here is unsourced.
- A newly identified remote access trojan named ChainScript uses lures mimicking popular software like Spotify and Microsoft Teams to infect Windows systems.
- The malware leverages Polygon smart contracts for command-and-control infrastructure discovery to evade detection.
- Attackers use these techniques to gain full remote control over compromised systems, including executing commands and stealing cryptocurrency wallet data.
- This development highlights an increasing trend of threat actors utilizing decentralized blockchain infrastructure for resilient malware operations.
What to watch next
- Emergence of additional ChainScript build names
- Continued use of blockchain-based C2 resolution in malware
- Evolution of ClickFix techniques to bypass security heuristics
Coverage1
1 report
English national1
All filed from India
Named United States · United Kingdom · Germany · Japan · Canada · France · Singapore · Australia · India · Netherlands · HBO Max · Microsoft Teams · Reddit · Spotify · Zoom Workplace · ADAMnetworks · Andi Ursry · Blackpoint Adversary Pursuit Group · ChainScript · Chandra Kant Bauri · Hudson Rock · Nevan Beal
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
