- Threat actors are deploying a new remote access trojan called ChainScript via ClickFix lures, using a Polygon smart contract for command-and-control discovery.
- ChainScript masquerades as Spotify, Zoom Workplace, or Microsoft Teams and provides full remote access, including cryptocurrency wallet enumeration.
- A separate ClickFix campaign compromised HBO Max’s official Reddit account to spread info-stealers like MacSync and Amatera to Windows and macOS users.
- Another campaign uses fake Codex download pages to trick macOS users into pasting malicious Terminal commands, delivering Atomic Stealer.
Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan called ChainScript, according to Blackpoint Adversary Pursuit Group. ChainScript has appeared under multiple build names while presenting itself as Spotify, Zoom Workplace, and Microsoft Teams software. Like many recent malware families, ChainScript employs an EtherHiding-style technique that makes use of a Polygon smart contract to locate its active WebSocket infrastructure. The RAT provides extensive remote access, including interactive CMD and PowerShell, file operations, screenshot capture, payload deployment, cryptocurrency wallet enumeration, and remote JavaScript execution. The attack chain begins with a ClickFix lure that leads to a malicious Windows installer disguised as Spotify, which deploys the Node.js runtime and launches the ChainScript JavaScript agent through hidden PowerShell and VBScript stages. The running agent establishes user-level persistence and connects to the C2 server over WebSockets, giving the threat actor direct control over the compromised system. Blackpoint noted that ChainScript reflects an emerging pattern of malware using blockchain-based C2 discovery to enable infrastructure rotation and complicate traditional indicator-based detection.
Meanwhile, threat actors compromised HBO Max’s official Reddit account and abused it to push malicious ads that launched ClickFix attacks, an activity dubbed PasteSwitch by Hudson Rock and ADAMnetworks. On macOS, PasteSwitch delivered MacSync, Atomic macOS Stealer, and fake cryptocurrency wallet applications designed to steal recovery phrases. The Windows branch distributed Amatera Stealer and cryptocurrency clippers like AnimateClipper and ZigClipper. The verified Reddit account served 108 malicious ads over 48 hours in mid-September 2026. Seqrite Labs reported that MacSync infections have concentrated in the U.S., followed by other regions with widespread macOS enterprise use and active cryptocurrency communities. Additionally, a separate ClickFix campaign uses a fake Codex download experience surfaced via search results to lead macOS users to bogus Google Sites pages, tricking them into pasting a malicious command into Terminal. Cato Networks explained that the copied command retrieves a multi-stage shell-script loader that ultimately executes a Mach-O payload. Microsoft observed a similar macOS ClickFix campaign using over 250 look-alike domains, with server-side browser-fingerprinting gates to limit visibility to sandboxes and automated analysis.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
