HackerFeeds

CyberSecurity News

ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

The Hacker News
· September 21, 2026

AI summary

Threat actors are using lures similar to ClickFix to deploy a newly discovered remote access trojan called ChainScript. ChainScript has been identified under various build names, including ComponentTask33 and OrchidViolet66. This malware disguises itself as legitimate software, such as Spotify, Zoom Workplace, and Microsoft Teams. The ChainScript RAT is being used to rotate command and control infrastructure using Polygon.

Read the full article at The Hacker Newsthehackernews.com/2026/09/clickfix-lures-deploy-chainscript-rat.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.