PGH Networks

ClickFix Fake Updates Are Now Delivering ChainScript RAT

September 21, 2026· PGH Networks Team· 5 min readBusiness & Tech Insights
ClickFix Fake Updates Are Now Delivering ChainScript RAT

What happened

Researchers at Blackpoint's Adversary Pursuit Group have documented a previously unnamed remote access trojan they're calling ChainScript, delivered through ClickFix-style lures, the fake "verify you're human" or "finish this update" prompts that trick a user into pasting a command into their own machine. The reporting, picked up via feeds.feedburner.com, is here: ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure.

Two details matter most for the businesses we support. First, ChainScript has shipped under several build names, including ComponentTask33, UpdateDigital, HostShared and OrchidViolet66, and it disguises itself as Spotify, Zoom Workplace and Microsoft Teams software. Second, per the headline, the operators are using the Polygon blockchain to rotate command-and-control infrastructure, which makes simple domain and IP blocklists a weak control. Technical specifics beyond that, exact hashes, initial landing pages, whether macOS is affected, aren't something we're going to guess at; ask your security provider to confirm current indicators against the published research rather than relying on a summary.

people working at desks in open office

Why this matters for Pittsburgh small and mid-sized businesses

The impersonated brands are the tell. Teams and Zoom are the two applications your staff sees prompts from most often, and both legitimately update themselves in ways most users don't fully understand. A CPA firm in Green Tree, a title practice downtown, a specialty clinic in Monroeville, these are environments where an accountant or paralegal sees "Microsoft Teams needs to finish updating" at 4:45 p.m. on a deadline day and clicks through without a second thought. ClickFix works precisely because it doesn't need an exploit. It needs a busy person who trusts their own screen.

That's also why this class of attack cuts past a lot of the spend SMBs have already made. There's no malicious attachment for your mail filter to strip. The user runs the command themselves, from a legitimate shell, on a machine they're already logged into. A RAT landing on a workstation in a 40-person firm typically means the attacker inherits whatever that person can reach: the document management system, mapped drives, the practice management database, saved browser credentials, and an authenticated Microsoft 365 session for mailbox access and internal phishing.

The compliance math gets ugly fast. For healthcare clients, unauthorized access to a system holding PHI starts a HIPAA breach-assessment clock, and "we couldn't tell what was accessed" almost always resolves against you. Financial services and accounting firms under the FTC Safeguards Rule are expected to detect and respond, not just prevent. For our defense-contractor clients, a RAT on an endpoint that touches CUI is a CMMC problem and potentially a DFARS 7012 reporting obligation, and the 72-hour incident reporting expectation means the decision window is measured in hours, not weeks. Manufacturers with flat networks between office and plant floor should assume lateral movement is the goal, not the mailbox.

And there's a 2026 wrinkle: as more firms roll out AI assistants, a compromised session doesn't just expose files, it can expose whatever the assistant is permissioned to summarize. If Copilot is on your roadmap, get the AI readiness assessment and permissions cleanup done before the rollout, not after.

What to do about it this week

  1. Send a plain-English warning to every employee today. One short message: no legitimate update from Teams, Zoom, Spotify, Windows or your browser will ever ask you to copy and paste a command, open the Run box, or type into a terminal. If you see that, stop and call the help desk. Name the brands, because specificity is what makes people remember.
  2. Kill the delivery mechanism where you can. Ask your IT provider to restrict or monitor the Windows Run dialog and clipboard-to-shell activity, and to enable constrained language mode or script-block logging for PowerShell on standard user workstations. Confirm what your current managed IT tooling supports before assuming it's covered.
  3. Verify EDR coverage and, more importantly, response. Detection that only emails an alert at 2 a.m. isn't a control. Ask directly: what percentage of endpoints report healthy, and who isolates a host at 2 a.m.? That's the difference between EDR and a monitored MDR service.
  4. Assume blocklists will lag. Because C2 infrastructure is being rotated through blockchain lookups, prioritize egress controls, DNS filtering with category-based blocking, and behavioral detection over IP-based rules. Ask whether your stack can alert on unusual outbound patterns from a workstation.
  5. Standardize how software actually gets installed and updated. If updates are pushed centrally and users can't install software, the fake-update pretext loses most of its power. Removing local admin rights is the single highest-value change most 10-to-200-person firms still haven't made.
  6. Harden the identity layer for the "after." Phishing-resistant MFA, conditional access by device compliance, and short session lifetimes limit what a stolen token buys. Review HIPAA, SOC 2 and NIST-aligned logging retention at the same time, since you'll need those logs to answer "what was accessed."
  7. Tabletop it before the end of the month. Thirty minutes: an endpoint is confirmed compromised on September 24. Who isolates it, who calls counsel, who decides whether a regulator or DoD reporting clock has started? Write down the gaps and assign owners. Your vCIO should be driving this, not IT alone.

How we help

PGH Networks manages endpoint hardening, patch and privilege controls, monitored detection and response, and identity configuration for small and mid-sized firms across Western Pennsylvania, and we map those controls to the framework you actually answer to, whether that's HIPAA, SOC 2, FTC Safeguards, or CMMC Level 2. If you're not sure whether your users could be talked into pasting a command today, that's a question worth answering this week rather than after an incident.

Call us at 724.888.7007 or reach out through the contact form and we'll walk your environment against this specific attack pattern.

Share

Related reading

Call usBook a meeting