ChainScript Trojan Has Used Smart Contracts for Attacks

Threat actors deployed a new remote access trojan that uses decentralized infrastructure to evade detection.

Updated on Sept. 21, 2026 in Cybersecurity

Isometric editorial illustration showing a monolithic server rack connected to a geometric node lattice, representing decentralized blockchain command infrastructure.
The new ChainScript remote access trojan is bypassing security defenses by utilizing decentralized blockchain smart contracts for its command-and-control communications. AI Illustration. Upload story photo >

Live Poll

Do you trust that social media platforms are doing enough to keep advertisements safe for users?

Hackers have launched a sophisticated remote access trojan called ChainScript that utilizes Polygon smart contracts for command-and-control communication. The malware masquerades as popular software like Spotify, Zoom, and Microsoft Teams to infect user systems.

Why it matters

By leveraging decentralized blockchain infrastructure, threat actors can effectively resist traditional takedown efforts. This decentralized approach ensures that malicious operations remain active and difficult for security researchers to disrupt.

The ChainScript agent is deployed via Node.js and executed through PowerShell and VBScript, maintaining persistence through scheduled tasks. Attackers utilized 250 look-alike domains to facilitate the ClickFix lure and subsequent malware installation.

The players

Microsoft

This technology corporation provides the Windows and macOS operating systems often targeted by large-scale malware campaigns.

HBO Max

This premium streaming service had an official Reddit account compromised to host malicious advertisements.

The details

The malware performs invasive operations such as file exfiltration, screenshot capture, and cryptocurrency wallet enumeration. Infection begins when users engage with ClickFix lures that trigger the download of malicious Windows installers.

Timeline

  1. In mid-September 2026, threat actors served 108 malicious ads over 48 hours.

  2. In August 2026, Microsoft reported on macOS ClickFix campaigns.

The Tech Race

The integration of decentralized smart contracts into malware command structures represents a significant evolution in evasion technology. This development forces cybersecurity defenders to expand monitoring capabilities beyond traditional web infrastructure to include blockchain-based communication protocols.

Users should exercise extreme caution when downloading software that appears to be from known brands like Zoom, Spotify, or Microsoft Teams. Verifying the source of any installer remains the primary defense against falling victim to these look-alike domain campaigns.

The takeaway

The use of legitimate, high-traffic platforms to serve malicious ads highlights the importance of skeptical browsing habits. Security teams must now account for blockchain-based infrastructure when analyzing communication channels used by modern malware strains.

Further reading

For broader trends in digital threat detection, see our coverage on Cybersecurity.

Live Poll

Do you trust that social media platforms are doing enough to keep advertisements safe for users?