When Malware Uses the Blockchain

Overview

A newly documented remote access trojan called ChainScript is combining ClickFix-style social engineering with an increasingly important cybercrime technique: using blockchain infrastructure to dynamically locate its command-and-control servers. Researchers at Blackpoint Cyber discovered the Node.js-based malware while investigating ClickFix activity involving a malicious Windows installer disguised as legitimate software such as Spotify, Zoom Workplace and Microsoft Teams. Once installed, ChainScript gives attackers extensive remote control, including CMD and PowerShell access, file operations, screenshots, payload deployment, cryptocurrency wallet discovery and remote JavaScript execution. The bigger security concern, however, lies in how compromised machines locate the attackers controlling them.

From ClickFix to Full Remote Access

The attack begins with ClickFix-style activity that persuades the user to execute a malicious Windows installer through msiexec.exe. The installer deploys its own Node.js runtime and launches the ChainScript agent through hidden PowerShell and VBScript stages. Persistence is established through a scheduled task, with a Registry Run key available as a fallback. Importantly, the analysed infection chain operates within the user’s context and does not initially require administrator privileges. Once connected, the attacker effectively has a persistent remote administration channel into the compromised machine.

The Blockchain Becomes a C2 Resolver

ChainScript’s most interesting capability is its use of a Polygon smart contract to locate the current command-and-control server. Instead of permanently hardcoding a C2 domain into the malware, the implant queries the blockchain and retrieves the address of the active WebSocket infrastructure. During Blackpoint’s investigation, the same smart contract initially pointed infected systems toward one C2 server and later redirected them to another. This means defenders may block a malicious domain or IP only for the attacker to update the external resolver and redirect infected systems elsewhere. The malware itself does not need to be rebuilt or redistributed.

Why Traditional IOC Blocking Is Not Enough

Security operations often rely heavily on indicators of compromise such as domains, IP addresses and URLs. Those remain useful, but ChainScript demonstrates their limitations against rapidly rotating infrastructure. If the attacker’s backend can change while the endpoint implant remains unchanged, static indicators quickly become outdated. Detection therefore needs to focus increasingly on behaviour and attack chains: unusual msiexec.exe execution, hidden PowerShell and VBScript activity, bundled Node.js runtimes in user directories, unexpected scheduled tasks, blockchain RPC queries followed by outbound WebSocket connections, and suspicious child-process relationships. Blackpoint specifically recommends treating infrastructure indicators as short-lived and prioritising persistent host and behavioural characteristics instead.

What IT Leaders Should Consider

Organisations should continue educating users that websites asking them to paste commands, launch Windows Run, execute PowerShell or perform unusual installation steps should be treated as suspicious. Endpoint controls can restrict user-initiated script execution and MSI installation where business requirements allow. EDR and XDR platforms should also correlate process, network and persistence behaviour rather than evaluating individual events in isolation. ClickFix itself is continuing to evolve: Microsoft has documented campaigns that fingerprint visitors and selectively expose malicious instructions only to suitable targets, helping attackers hide from crawlers and automated analysis.

Expert in the Cloud Insight

ChainScript demonstrates a broader change in attacker architecture: malware infrastructure is becoming more modular, distributed and resilient. The blockchain is not inherently malicious, but its availability and decentralised design can be abused as an external directory that tells malware where its operators have moved. For CIOs and security leaders, the important question is therefore no longer simply: “Have we blocked the malicious IP or domain?” It should also be: “Can we still recognise the attack when that infrastructure changes?” Indicators expire. Behaviour survives. As attackers become better at rotating infrastructure, effective defence increasingly depends on understanding how an intrusion operates, not only where it connects.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.