Threat Advisory

ChainScript RAT Enables Broad Remote Entry Features with MSI Packages

Threat: Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

ChainScript is a Node.js-based remote access trojan delivered through ClickFix activity using malicious MSI installers disguised as legitimate applications such as Spotify Spotify Workplace and Microsoft Teams. The malware establishes user-level persistence before connecting to its command-and-control infrastructure. Multiple builds were identified under different names while retaining consistent components and core functionality.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

ChainScript is a Node.js-based remote access trojan delivered through ClickFix activity using malicious MSI installers disguised as legitimate applications such as Spotify Spotify Workplace and Microsoft Teams. The malware establishes user-level persistence before connecting to its command-and-control infrastructure. Multiple builds were identified under different names while retaining consistent components and core functionality.[emaillocker id="1283"]

The infection chain begins when ClickFix activity convinces a user to execute a command that retrieves a malicious MSI installer. The installer deploys a bundled Node.js runtime and launches the ChainScript agent through hidden PowerShell and VBScript components. Persistence is established through a scheduled task with a Run key fallback. ChainScript uses a Polygon smart contract to dynamically discover its active WebSocket C2 server which enables infrastructure rotation without modifying the deployed agent. The RAT supports command execution through CMD and PowerShell interactive shell sessions file operations screenshots payload deployment wallet discovery remote JavaScript execution agent updates and cleanup. It can also retrieve additional JavaScript modules that extend its command capabilities.

ChainScript combines remote access capabilities with blockchain-based C2 discovery to provide operators with flexible control over compromised Windows systems. Its use of changing build names legitimate software lures and rotating C2 infrastructure can complicate traditional indicator-based detection. The observed capabilities allow compromised hosts to execute commands transfer files capture screenshots deploy additional payloads and maintain persistent access. Organizations should therefore monitor ClickFix activity suspicious MSI and script execution Node.js processes user-level persistence mechanisms plus unexpected blockchain RPC and WebSocket communications.

 

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.002 Phishing Spearphishing Link
Execution T1059.001 Command and Scripting Interpreter PowerShell
Execution T1059.005 Command and Scripting Interpreter Visual Basic
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Command and control T1571 Non Standard Port-
Exfiltration T1041 Exfiltration Over C2 Channel -

 

MBC PROFILE:

Objective Behavior ID Behavior
Command & Control B0030 C2 Communication
Impact B0022 Remote Access
Execution E1204 User Execution
Persistence F0012 Registry Run Keys / Startup Folder
Exfiltration E1020 Automated Exfiltration
Discovery E1082 System Information Discovery
Anti-Static Analysis B0032 Executable Code Obfuscation
Anti-Static Analysis E1027 Obfuscated Files or Information

 

REFERENCES:

The following reports contain further technical details:
https://blackpointcyber.com/blog/chainscript-tracing-a-nodejs-rat-across-the-blockchain/

 

[/emaillocker]
crossmenu