Return to Threats

ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

thehackernews.com 2026-09-21 malicious AI use High

What Happened

Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript. "ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while presenting itself as Spotify, Zoom Workplace, and Microsoft Teams software," Blackpoint Adversary Pursuit Group (APG)

Why It Matters

Report facts: The article describes threat actors using ClickFix-style lures to distribute a new remote access trojan (RAT) named ChainScript, which masquerades under multiple build names and impersonates popular software like Spotify, Zoom Workplace, and Microsoft Teams. It also notes the use of Polygon-based infrastructure rotation for command-and-control, complicating takedown and tracking. RealGround analysis: While the campaign targets traditional endpoints rather than AI systems directly, similar techniques—fake productivity apps and rapidly rotating infrastructure—could be used to infiltrate environments where AI agents operate or compromise the software supply chain feeding AI tools. Organizations should harden download and update channels, monitor for anomalous binaries and rotating C2 patterns, and integrate continuous red teaming and SBOM-based supply chain review to detect malware that might later be leveraged to manipulate or surveil AI systems.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to malicious AI use. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/09/clickfix-lures-deploy-chainscript-rat.html

Talk to AI CISO