{"id":1880,"date":"2026-09-22T13:45:37","date_gmt":"2026-09-22T08:15:37","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1880"},"modified":"2026-09-24T17:24:13","modified_gmt":"2026-09-24T11:54:13","slug":"chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\/","title":{"rendered":"ChainScript Uses ClickFix and Polygon to Keep RAT Infrastructure Moving"},"content":{"rendered":"<p>ClickFix malware delivery is taking another form with ChainScript, a remote access trojan investigated by Blackpoint\u2019s Adversary Pursuit Group. Its installers impersonate Spotify, Zoom Workplace, and Microsoft Teams, with builds named ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66. The campaign combines familiar software branding with attacker-controlled execution. Blackpoint\u2019s analysis documents the findings.<\/p>\n<p>For security administrators and SOC analysts, the priority is understanding what happens after someone follows the lure. A trusted-looking installer can begin a sequence that ends with persistent remote access.<\/p>\n<h2>How ClickFix malware delivers the ChainScript agent<\/h2>\n<p>The analyzed infection starts when a user runs msiexec.exe to retrieve a malicious MSI. Hidden PowerShell and VBScript stages prepare and launch a bundled Node.js runtime, which executes app\\src\\index.js.<\/p>\n<p>The agent then establishes persistence through a scheduled task at user logon, falling back to an HKCU Registry Run entry. Installation and persistence operate within the user\u2019s context without requiring administrator privileges.<\/p>\n<p>For defenders, this means an investigation should examine the user profile and subsequent launches even when no privilege elevation occurred.<\/p>\n<h3>Investigating a suspected ClickFix malware execution chain<\/h3>\n<p>Look for installer activity followed by wscript.exe launching ._agent.vbs, then a bundled node.exe running the agent. Review subsequent PowerShell activity that creates persistence.<\/p>\n<p>Ask whether the runtime belongs to approved software and whether the user expected that installation. Record the initiating website and download source alongside endpoint evidence.<\/p>\n<h2>What attackers can do after compromise<\/h2>\n<p>ChainScript supports interactive CMD and <a href=\"https:\/\/www.hexnode.com\/blogs\/the-beginners-guide-to-powershell-scripting\/\">PowerShell<\/a>, file operations, screenshots, payload deployment, JavaScript execution, self-updates, and persistence removal. Its wallet function enumerates wallets and extensions. Researchers did not identify dedicated seed-phrase or private-key extraction, although broader remote access remains a concern.<\/p>\n<p>Prioritize systems holding sensitive business information. Document accessible resources, investigate potential secondary activity, and determine which accounts require recovery measures.<\/p>\n<p>Structure the response around questions the team can answer with evidence: Who used the device? Which business services were accessible? What changed after the installer ran? Preserve relevant records and assign an owner to each unresolved question. Use those findings to decide whether recovery requires rebuilding the endpoint, resetting credentials, or expanding the investigation to other systems and users.<\/p>\n<h2>Why Polygon changes C2 blocking<\/h2>\n<p>ChainScript queries a Polygon smart contract to discover its active WebSocket command-and-control server. Blackpoint observed the resolved backend change during analysis, demonstrating infrastructure rotation without replacing the implant.<\/p>\n<p>The blockchain serves as a discovery mechanism; operator communication then uses the resolved WebSocket infrastructure. This separation lets deployed agents locate replacement servers.<\/p>\n<p>Treat blocking a known server as one containment step. Before closing an incident, verify the endpoint\u2019s state and investigate whether attacker access persists.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit.webp?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity-kit\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit.webp?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit-300x225.webp?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit-768x576.webp?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cybersecurity-kit-133x100.webp?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity-kit\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured Resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Cybersecurity kit\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Access essential cybersecurity resources to strengthen security, reduce risk, and improve cyber resilience.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/resource-kits\/cybersecurity-kit\/'>\n                            Download the Resource Kit\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>How Hexnode supports investigation and response<\/h2>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> helps administrators investigate endpoint activity and review parent-child relationships through its visual process tree. For ChainScript, analysts should examine the execution sequence involving msiexec.exe, wscript.exe, and node.exe. After identifying the relevant parent process, administrators can initiate Kill Process Tree to terminate that process and its children. Selecting the correct parent matters because terminating a child does not terminate its ancestors. Hexnode\u2019s process termination guidance explains these actions.<\/p>\n<p>Administrators can also initiate Isolate Device to block general network communication while preserving the connection to the Hexnode XDR console for continued investigation. Quarantine File contains the malicious payload in a restricted, encrypted location. These actions complement process termination; teams must also remove persistence mechanisms and investigate secondary payloads. Hexnode XDR response capabilities support these containment steps.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> adds application governance:<\/p>\n<table>\n<thead>\n<tr>\n<th>Security objective<\/th>\n<th>Hexnode capability and application<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Restrict unapproved executables<\/td>\n<td>Windows Blocklist\/Allowlist supports publisher or file-path rules for executables. Apply tested rules to the intended device groups.<\/td>\n<\/tr>\n<tr>\n<td>Identify application policy violations<\/td>\n<td>Windows Application Compliance checks installed applications against configured blocklists or allowlists. Administrators must manually enable <strong>Device is not application compliant<\/strong> under <strong>Admin &gt; General Settings &gt; Compliance Settings<\/strong>. Without this setting, application policy violations will not mark the device as non-compliant. Application Compliance does not block application installation or execution.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Application Compliance supports Windows 10 and Windows 11 Pro, Enterprise, and Education, excluding Home. Devices must run Hexnode Agent 4.8.0 or later. Application Compliance documentation details these requirements.<\/p>\n<p>Pilot application restrictions with representative users before wider deployment. Confirm that approved business applications function and document how analysts escalate suspicious installations.<\/p>\n<h3>FAQs<\/h3>\n<p><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">How does ClickFix malware deliver ChainScript to Windows devices?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>The analyzed ChainScript infection begins when a user runs msiexec.exe to retrieve a malicious MSI. Hidden PowerShell and VBScript stages then launch a bundled Node.js runtime that executes the ChainScript agent.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Does ChainScript require administrator privileges to establish persistence?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>No. The analyzed ChainScript installation and persistence mechanisms operate within the user&#8217;s context without requiring administrator privileges. The malware can create a scheduled task at user logon and fall back to an HKCU Registry Run entry.<\/p>\n<\/div><\/div><\/div> <div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">How does ChainScript use the Polygon blockchain for command and control?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>ChainScript queries a Polygon smart contract to discover its current WebSocket command-and-control server. This separates C2 discovery from operator communication, allowing deployed agents to locate replacement infrastructure when the backend changes.<\/p>\n<\/div><\/div><\/div><\/p>\n<h3>Build response around the compromised endpoint<\/h3>\n<p>ChainScript reinforces the need to connect user reports, execution evidence, and containment decisions. Train employees to report unexpected command prompts. Give analysts a clear escalation path and authority to contain confirmed threats. Validate recovery before returning affected devices to normal business use.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen RAT Detection and Response<\/h5><p>Detect suspicious endpoint activity, investigate threats, and contain malicious processes faster with Hexnode.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Start Your Free Trial! <\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>ClickFix malware delivery is taking another form with ChainScript, a remote access trojan investigated by&#8230;<\/p>\n","protected":false},"author":6,"featured_media":1971,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[15,16],"class_list":["post-1880","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware","category-windows","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>ClickFix Malware Deploys ChainScript RAT via Fake Installers<\/title>\n<meta name=\"description\" content=\"ClickFix malware delivers ChainScript RAT using fake installers and Polygon-based C2 discovery. Learn how to investigate and contain endpoint threats.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"ClickFix Malware Deploys ChainScript RAT via Fake Installers\" \/>\n<meta property=\"og:description\" content=\"ClickFix malware delivers ChainScript RAT using fake installers and Polygon-based C2 discovery. Learn how to investigate and contain endpoint threats.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-22T08:15:37+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-24T11:54:13+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/ChainScript-Uses-ClickFix-and-Polygon-to-Keep-RAT-Infrastructure-Moving.png?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Lily Anne\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lily Anne\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\\\/\"},\"author\":{\"name\":\"Lily Anne\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\"},\"headline\":\"ChainScript Uses ClickFix and Polygon to Keep RAT Infrastructure Moving\",\"datePublished\":\"2026-09-22T08:15:37+00:00\",\"dateModified\":\"2026-09-24T11:54:13+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\\\/\"},\"wordCount\":935,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ChainScript-Uses-ClickFix-and-Polygon-to-Keep-RAT-Infrastructure-Moving.png?format=webp\",\"articleSection\":[\"Malware\",\"Windows\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\\\/\",\"name\":\"ClickFix Malware Deploys ChainScript RAT via Fake Installers\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ChainScript-Uses-ClickFix-and-Polygon-to-Keep-RAT-Infrastructure-Moving.png?format=webp\",\"datePublished\":\"2026-09-22T08:15:37+00:00\",\"dateModified\":\"2026-09-24T11:54:13+00:00\",\"description\":\"ClickFix malware delivers ChainScript RAT using fake installers and Polygon-based C2 discovery. Learn how to investigate and contain endpoint threats.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ChainScript-Uses-ClickFix-and-Polygon-to-Keep-RAT-Infrastructure-Moving.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ChainScript-Uses-ClickFix-and-Polygon-to-Keep-RAT-Infrastructure-Moving.png?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"ChainScript Uses ClickFix and Polygon to Keep RAT Infrastructure Moving\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"ChainScript Uses ClickFix and Polygon to Keep RAT Infrastructure Moving\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/072b33718ec5df7cb7dbb9bae93044fa\",\"name\":\"Lily Anne\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g\",\"caption\":\"Lily Anne\"},\"description\":\"Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/lily-anne\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"ClickFix Malware Deploys ChainScript RAT via Fake Installers","description":"ClickFix malware delivers ChainScript RAT using fake installers and Polygon-based C2 discovery. Learn how to investigate and contain endpoint threats.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\/","og_locale":"en_US","og_type":"article","og_title":"ClickFix Malware Deploys ChainScript RAT via Fake Installers","og_description":"ClickFix malware delivers ChainScript RAT using fake installers and Polygon-based C2 discovery. Learn how to investigate and contain endpoint threats.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-22T08:15:37+00:00","article_modified_time":"2026-09-24T11:54:13+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/ChainScript-Uses-ClickFix-and-Polygon-to-Keep-RAT-Infrastructure-Moving.png?format=webp","type":"image\/png"}],"author":"Lily Anne","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Lily Anne","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\/"},"author":{"name":"Lily Anne","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa"},"headline":"ChainScript Uses ClickFix and Polygon to Keep RAT Infrastructure Moving","datePublished":"2026-09-22T08:15:37+00:00","dateModified":"2026-09-24T11:54:13+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\/"},"wordCount":935,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/ChainScript-Uses-ClickFix-and-Polygon-to-Keep-RAT-Infrastructure-Moving.png?format=webp","articleSection":["Malware","Windows"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\/","url":"https:\/\/www.hexnode.com\/threat-watch\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\/","name":"ClickFix Malware Deploys ChainScript RAT via Fake Installers","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/ChainScript-Uses-ClickFix-and-Polygon-to-Keep-RAT-Infrastructure-Moving.png?format=webp","datePublished":"2026-09-22T08:15:37+00:00","dateModified":"2026-09-24T11:54:13+00:00","description":"ClickFix malware delivers ChainScript RAT using fake installers and Polygon-based C2 discovery. Learn how to investigate and contain endpoint threats.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/ChainScript-Uses-ClickFix-and-Polygon-to-Keep-RAT-Infrastructure-Moving.png?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/ChainScript-Uses-ClickFix-and-Polygon-to-Keep-RAT-Infrastructure-Moving.png?format=webp","width":1340,"height":700,"caption":"ChainScript Uses ClickFix and Polygon to Keep RAT Infrastructure Moving"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/chainscript-uses-clickfix-and-polygon-to-keep-rat-infrastructure-moving\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"ChainScript Uses ClickFix and Polygon to Keep RAT Infrastructure Moving"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/072b33718ec5df7cb7dbb9bae93044fa","name":"Lily Anne","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a5e6255489d50e4ae3ff1f9194f7ae879725d6b1d5eb4c9ec7a7f9ba3f66124e?s=96&d=mm&r=g","caption":"Lily Anne"},"description":"Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/lily-anne\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1880","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1880"}],"version-history":[{"count":4,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1880\/revisions"}],"predecessor-version":[{"id":1952,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1880\/revisions\/1952"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1971"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1880"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1880"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}