EXECUTIVE SUMMARY:
ChainScript is a Node.js-based remote access trojan delivered through ClickFix activity using malicious MSI installers disguised as legitimate applications such as Spotify Spotify Workplace and Microsoft Teams. The malware establishes user-level persistence before connecting to its command-and-control infrastructure. Multiple builds were identified under different names while retaining consistent components and core functionality.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
ChainScript is a Node.js-based remote access trojan delivered through ClickFix activity using malicious MSI installers disguised as legitimate applications such as Spotify Spotify Workplace and Microsoft Teams. The malware establishes user-level persistence before connecting to its command-and-control infrastructure. Multiple builds were identified under different names while retaining consistent components and core functionality.[emaillocker id="1283"]
The infection chain begins when ClickFix activity convinces a user to execute a command that retrieves a malicious MSI installer. The installer deploys a bundled Node.js runtime and launches the ChainScript agent through hidden PowerShell and VBScript components. Persistence is established through a scheduled task with a Run key fallback. ChainScript uses a Polygon smart contract to dynamically discover its active WebSocket C2 server which enables infrastructure rotation without modifying the deployed agent. The RAT supports command execution through CMD and PowerShell interactive shell sessions file operations screenshots payload deployment wallet discovery remote JavaScript execution agent updates and cleanup. It can also retrieve additional JavaScript modules that extend its command capabilities.
ChainScript combines remote access capabilities with blockchain-based C2 discovery to provide operators with flexible control over compromised Windows systems. Its use of changing build names legitimate software lures and rotating C2 infrastructure can complicate traditional indicator-based detection. The observed capabilities allow compromised hosts to execute commands transfer files capture screenshots deploy additional payloads and maintain persistent access. Organizations should therefore monitor ClickFix activity suspicious MSI and script execution Node.js processes user-level persistence mechanisms plus unexpected blockchain RPC and WebSocket communications.
THREAT PROFILE:
| Tactic | Technique Id | Technique | Sub-technique |
| Initial access | T1566.002 | Phishing | Spearphishing Link |
| Execution | T1059.001 | Command and Scripting Interpreter | PowerShell |
| Execution | T1059.005 | Command and Scripting Interpreter | Visual Basic |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Command and control | T1571 | Non | Standard Port- |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
MBC PROFILE:
| Objective | Behavior ID | Behavior |
| Command & Control | B0030 | C2 Communication |
| Impact | B0022 | Remote Access |
| Execution | E1204 | User Execution |
| Persistence | F0012 | Registry Run Keys / Startup Folder |
| Exfiltration | E1020 | Automated Exfiltration |
| Discovery | E1082 | System Information Discovery |
| Anti-Static Analysis | B0032 | Executable Code Obfuscation |
| Anti-Static Analysis | E1027 | Obfuscated Files or Information |
REFERENCES:
The following reports contain further technical details:
https://blackpointcyber.com/blog/chainscript-tracing-a-nodejs-rat-across-the-blockchain/
[/emaillocker]