Lily
Anne

ChainScript Uses ClickFix and Polygon to Keep RAT Infrastructure Moving

Lily Anne

Sep 22, 2026

5 min read

ChainScript Uses ClickFix and Polygon to Keep RAT Infrastructure Moving

TL; DR

ClickFix malware is delivering ChainScript through trusted-looking software installers, giving attackers persistent remote access while using Polygon to keep command-and-control discovery flexible.

  • The infection chain uses a malicious MSI, hidden PowerShell and VBScript stages, Node.js execution, and user-level persistence without requiring administrator privileges.
  • ChainScript supports command execution, file operations, screenshots, payload deployment, remote JavaScript execution, self-updates, and wallet enumeration.
  • Hexnode XDR can support endpoint investigation and containment, while Hexnode UEM adds Windows application controls and compliance checks for governing unapproved software.

ClickFix malware delivery is taking another form with ChainScript, a remote access trojan investigated by Blackpoint’s Adversary Pursuit Group. Its installers impersonate Spotify, Zoom Workplace, and Microsoft Teams, with builds named ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66. The campaign combines familiar software branding with attacker-controlled execution. Blackpoint’s analysis documents the findings.

For security administrators and SOC analysts, the priority is understanding what happens after someone follows the lure. A trusted-looking installer can begin a sequence that ends with persistent remote access.

How ClickFix malware delivers the ChainScript agent

The analyzed infection starts when a user runs msiexec.exe to retrieve a malicious MSI. Hidden PowerShell and VBScript stages prepare and launch a bundled Node.js runtime, which executes app\src\index.js.

The agent then establishes persistence through a scheduled task at user logon, falling back to an HKCU Registry Run entry. Installation and persistence operate within the user’s context without requiring administrator privileges.

For defenders, this means an investigation should examine the user profile and subsequent launches even when no privilege elevation occurred.

Investigating a suspected ClickFix malware execution chain

Look for installer activity followed by wscript.exe launching ._agent.vbs, then a bundled node.exe running the agent. Review subsequent PowerShell activity that creates persistence.

Ask whether the runtime belongs to approved software and whether the user expected that installation. Record the initiating website and download source alongside endpoint evidence.

What attackers can do after compromise

ChainScript supports interactive CMD and PowerShell, file operations, screenshots, payload deployment, JavaScript execution, self-updates, and persistence removal. Its wallet function enumerates wallets and extensions. Researchers did not identify dedicated seed-phrase or private-key extraction, although broader remote access remains a concern.

Prioritize systems holding sensitive business information. Document accessible resources, investigate potential secondary activity, and determine which accounts require recovery measures.

Structure the response around questions the team can answer with evidence: Who used the device? Which business services were accessible? What changed after the installer ran? Preserve relevant records and assign an owner to each unresolved question. Use those findings to decide whether recovery requires rebuilding the endpoint, resetting credentials, or expanding the investigation to other systems and users.

Why Polygon changes C2 blocking

ChainScript queries a Polygon smart contract to discover its active WebSocket command-and-control server. Blackpoint observed the resolved backend change during analysis, demonstrating infrastructure rotation without replacing the implant.

The blockchain serves as a discovery mechanism; operator communication then uses the resolved WebSocket infrastructure. This separation lets deployed agents locate replacement servers.

Treat blocking a known server as one containment step. Before closing an incident, verify the endpoint’s state and investigate whether attacker access persists.

cybersecurity-kit

Cybersecurity kit

Access essential cybersecurity resources to strengthen security, reduce risk, and improve cyber resilience.

Download the Resource Kit

How Hexnode supports investigation and response

Hexnode XDR helps administrators investigate endpoint activity and review parent-child relationships through its visual process tree. For ChainScript, analysts should examine the execution sequence involving msiexec.exe, wscript.exe, and node.exe. After identifying the relevant parent process, administrators can initiate Kill Process Tree to terminate that process and its children. Selecting the correct parent matters because terminating a child does not terminate its ancestors. Hexnode’s process termination guidance explains these actions.

Administrators can also initiate Isolate Device to block general network communication while preserving the connection to the Hexnode XDR console for continued investigation. Quarantine File contains the malicious payload in a restricted, encrypted location. These actions complement process termination; teams must also remove persistence mechanisms and investigate secondary payloads. Hexnode XDR response capabilities support these containment steps.

Hexnode UEM adds application governance:

Security objective Hexnode capability and application
Restrict unapproved executables Windows Blocklist/Allowlist supports publisher or file-path rules for executables. Apply tested rules to the intended device groups.
Identify application policy violations Windows Application Compliance checks installed applications against configured blocklists or allowlists. Administrators must manually enable Device is not application compliant under Admin > General Settings > Compliance Settings. Without this setting, application policy violations will not mark the device as non-compliant. Application Compliance does not block application installation or execution.

Application Compliance supports Windows 10 and Windows 11 Pro, Enterprise, and Education, excluding Home. Devices must run Hexnode Agent 4.8.0 or later. Application Compliance documentation details these requirements.

Pilot application restrictions with representative users before wider deployment. Confirm that approved business applications function and document how analysts escalate suspicious installations.

FAQs

The analyzed ChainScript infection begins when a user runs msiexec.exe to retrieve a malicious MSI. Hidden PowerShell and VBScript stages then launch a bundled Node.js runtime that executes the ChainScript agent.

No. The analyzed ChainScript installation and persistence mechanisms operate within the user’s context without requiring administrator privileges. The malware can create a scheduled task at user logon and fall back to an HKCU Registry Run entry.

ChainScript queries a Polygon smart contract to discover its current WebSocket command-and-control server. This separates C2 discovery from operator communication, allowing deployed agents to locate replacement infrastructure when the backend changes.

Build response around the compromised endpoint

ChainScript reinforces the need to connect user reports, execution evidence, and containment decisions. Train employees to report unexpected command prompts. Give analysts a clear escalation path and authority to contain confirmed threats. Validate recovery before returning affected devices to normal business use.

Share

Lily Anne

Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.