A New RAT Called ChainScript Is Spreading Through Fake Zoom and Teams Installers
Researchers just found a new remote access trojan called ChainScript, hidden inside fake Zoom, Teams and Spotify installers. It uses the same "paste this to fix it" trick behind the ClickFix scam we warned about in May, but with a twist that makes it much harder for security tools to block.
Blackpoint researchers reported on 21 September that ChainScript arrives through a download that looks like a normal Zoom, Teams or Spotify install, then quietly runs hidden PowerShell and script stages once opened. From there it gives an attacker interactive remote access: files, screenshots, payload deployment and cryptocurrency wallet enumeration. The part worth knowing is how it hides: instead of calling a fixed server, ChainScript looks up its control server through a Polygon blockchain contract, so attackers can swap infrastructure faster than blocklists and antivirus vendors can keep up.
Our May alert covered the core ClickFix trick and still applies: no legitimate site or update asks you to paste a command into Run, PowerShell or Terminal. What's new here is the delivery method, a convincing fake app install rather than a fake CAPTCHA, which is why the advice needs an extra layer. In the environments we manage, the control that actually stops this pattern isn't URL or IP blocking, since that infrastructure keeps rotating: it's restricting who can install new software and run installers in the first place, on top of the staff awareness we already recommended.
Written by Dan Briggs, Head of Client Partnerships, All IT Services. All IT is a Sydney-based managed IT provider supporting hospitality, not-for-profit and wealth management businesses across Australia.
Frequently Asked Questions
Not sure who can install software on your network?
We can help you lock down installs and train your team to spot scams like this before they cost you.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
Read the Full Guide →
