Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
“ChainScript invokes StreamServiceSharedBridge.ps1, which first attempts to create a hidden ComponentTask33Agent scheduled task at user logon.”
“Hidden PowerShell launched ._scatter.ps1” and “PowerShell tasks write operator content to %TEMP%\wra-ps-* before starting powershell.exe with -NoProfile, -NonInteractive, and -ExecutionPolicy Bypass.”
“cmd tasks launch cmd.exe /c” and “Shell sessions support start, input, resize, and close actions.”
“wscript.exe executing ._agent.vbs” and “The script runs through wscript.exe and starts the bundled node.exe runtime.”
“The core ChainScript agent is the Node.js application rooted at app\src\index.js.”
“ChainScript first Base64 decodes the file, XORs the resulting bytes using a buildSeed value ... and parses the recovered JSON.”
“ChainScript has appeared under multiple build names ... while presenting itself as Spotify, Zoom Workplace, and Microsoft Teams software.”
Le MSI malveillant se présentant comme Spotify ... disperse ses composants dans des chemins imitant des répertoires Microsoft légitimes.
“The kill path removes persistence and creates temporary cleanup logic to delete the scattered installation directories.”
“[The agent] registers details including ... local IPv4 address, and domain or workgroup information.”
“The agent derives a stable host identity from the system hostname and Windows MachineGuid, then registers details including the username, architecture, uptime, memory, CPU count...”
“Once the panel is resolved, ChainScript connects over WebSockets and authenticates using the X-Agent-Token header.”
pour résoudre dynamiquement l’URL du panneau WebSocket actif.
“The malware uses an EtherHiding style C2 discovery technique that relies on a Polygon smart contract to locate its active WebSocket infrastructure.”
“The download_run handler stages arbitrary HTTP content under %TEMP%\agent-dl-* and launches it hidden or detached.”
“ChainScript is a full featured RAT that gives operators broad control over an infected system.”
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
RAT Node.js distribué via une campagne ClickFix et un MSI malveillant. Il établit sa persistance par tâche planifiée ou clé Run, résout dynamiquement son C2 WebSocket au moyen d’un smart contract Polygon (technique EtherHiding), et fournit des shells CMD/PowerShell, gestion de fichiers, capture d’écran, déploiement de charges utiles, inventaire de wallets crypto, exécution JavaScript distante, mise à jour et nettoyage.
A Node.js remote-access trojan delivered through ClickFix-driven malicious MSI installers. It uses a Polygon smart contract in an EtherHiding-style C2-discovery scheme to resolve and rotate WebSocket C2 infrastructure. It supports CMD and PowerShell execution, interactive shells, file operations, screenshots, payload deployment, wallet reconnaissance, remote JavaScript execution, self-update, and cleanup.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.