← Back to Crime & Security

Threat Actors Deploy ChainScript Trojan Using Blockchain for Command-and-Control Resilience

Crime & SecurityAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

Global cybersecurity defenders have identified a sophisticated campaign in which threat actors are deploying a new remote access trojan known as ChainScript, utilizing the Polygon blockchain to rotate command-and-control servers. The operation, attributed to the Blackpoint Adversary Pursuit Group (APG) and linked to infrastructure managed by Hudson Rock and ADAMnetworks, marks a significant shift toward decentralized networks for maintaining persistent access to compromised systems.

The campaign leverages deceptive lures centered on ClickFix, a service often associated with system repair tools, to distribute the malware. Once executed, the ChainScript trojan establishes communication channels that rely on blockchain transactions rather than traditional centralized servers. This architecture allows the operators to dynamically rotate their command-and-control infrastructure, making it significantly more difficult for security teams to trace and dismantle the network. The primary objective of this method is to resist takedown efforts and ensure uninterrupted operations by leveraging the immutable and distributed nature of blockchain technology for server discovery.

Infections have been detected across a wide geographic footprint, with a notable concentration of MacSync-related compromises in the United States, United Kingdom, Germany, Japan, Canada, France, Singapore, Australia, India, and the Netherlands. The malware targets macOS environments, exploiting user trust in legitimate-looking utility software to gain initial access. Security researchers observed that the use of ClickFix lures has become a primary vector for delivering the payload, disguising malicious scripts within what appears to be benign system optimization tools.

The involvement of Hudson Rock and ADAMnetworks suggests a coordinated effort to provide resilient backend support for these operations. By integrating Polygon blockchain infrastructure, the threat actors create a decentralized ledger that dictates where the malware should look for new instructions, effectively removing single points of failure that are common in traditional botnet architectures. This approach complicates mitigation strategies, as blocking individual IP addresses or domains becomes less effective when the control mechanism is distributed across a public ledger.

As of September 21, 2026, security firms continue to monitor the evolution of the ChainScript trojan. The deployment represents an escalation in adversarial tactics, moving beyond standard phishing and direct server compromises toward infrastructure that is inherently resistant to conventional disruption methods. Questions remain regarding the full scope of the campaign's financial motivations and whether other cryptocurrency networks will be adopted for similar command-and-control purposes. Defenders are currently working to develop detection signatures capable of identifying the blockchain-based communication patterns unique to this threat.

Discussion

0 / 2000