ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Summary
Threat actors are employing ClickFix-like lures to distribute a new remote access trojan (RAT) known as ChainScript. This RAT has been observed under various build names and disguised as legitimate software like Spotify, Zoom Workplace, and Microsoft Teams.
IFF Assessment
FOE
The discovery of a new RAT being actively deployed signifies a new tool for attackers, posing a direct threat to defenders.
Defender Context
Defenders should be aware of new RATs like ChainScript being distributed via social engineering lures. Vigilance in scrutinizing email attachments and downloads, especially those impersonating popular software, is crucial to prevent initial infection. Monitoring for indicators of compromise associated with this RAT will be important for detection and response.