CyberSecurity News
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
The Hacker News
· September 21, 2026AI summary
Threat actors are using lures similar to ClickFix to deploy a newly discovered remote access trojan called ChainScript. ChainScript has been identified under various build names, including ComponentTask33 and OrchidViolet66. This malware disguises itself as legitimate software, such as Spotify, Zoom Workplace, and Microsoft Teams. The ChainScript RAT is being used to rotate command and control infrastructure using Polygon.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

