Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Security alert graphic for ChainScript RAT malware spreading through fake Zoom and Teams installers

A New RAT Called ChainScript Is Spreading Through Fake Zoom and Teams Installers

Researchers just found a new remote access trojan called ChainScript, hidden inside fake Zoom, Teams and Spotify installers. It uses the same "paste this to fix it" trick behind the ClickFix scam we warned about in May, but with a twist that makes it much harder for security tools to block.

Blackpoint researchers reported on 21 September that ChainScript arrives through a download that looks like a normal Zoom, Teams or Spotify install, then quietly runs hidden PowerShell and script stages once opened. From there it gives an attacker interactive remote access: files, screenshots, payload deployment and cryptocurrency wallet enumeration. The part worth knowing is how it hides: instead of calling a fixed server, ChainScript looks up its control server through a Polygon blockchain contract, so attackers can swap infrastructure faster than blocklists and antivirus vendors can keep up.

Our May alert covered the core ClickFix trick and still applies: no legitimate site or update asks you to paste a command into Run, PowerShell or Terminal. What's new here is the delivery method, a convincing fake app install rather than a fake CAPTCHA, which is why the advice needs an extra layer. In the environments we manage, the control that actually stops this pattern isn't URL or IP blocking, since that infrastructure keeps rotating: it's restricting who can install new software and run installers in the first place, on top of the staff awareness we already recommended.

Written by Dan Briggs, Head of Client Partnerships, All IT Services. All IT is a Sydney-based managed IT provider supporting hospitality, not-for-profit and wealth management businesses across Australia.


Frequently Asked Questions

ChainScript is a remote access trojan spread through fake Zoom, Teams and Spotify installers. Once installed, it gives an attacker remote control of the device, including files, screenshots and cryptocurrency wallets.
It uses the same trick, tricking someone into running a command themselves, but through a different door: a fake app installer rather than a fake CAPTCHA on a hacked website. See our May alert for the original ClickFix explainer.
ChainScript looks up its control server through a Polygon blockchain contract instead of a fixed address, so attackers can swap servers faster than blocklists and antivirus vendors can update.
Restrict who can install software and run new installers, not just who can paste PowerShell commands, since this campaign hides inside what looks like a normal app download.

Not sure who can install software on your network?

We can help you lock down installs and train your team to spot scams like this before they cost you.


Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →