ChainScript Hides Its C2 in a Polygon Contract. Sixth Campaign We Have Typed That Way Since July. ThreatFox Had Four of Its Domains Two Weeks Early. The Contract Was in Nobody's Feed.
Blackpoint Cyber's Adversary Pursuit Group published an analysis this morning of a Node.js remote access trojan they call ChainScript. The delivery is ClickFix, the lure is a fake Spotify, Zoom or Teams installer, and the interesting part is the part that has stopped being interesting: it finds its command-and-control server by calling a smart contract on Polygon.
We ran all seventeen of their indicators against our corpus before writing a word. Here is what came back, and it splits three ways: what we held and did not earn, what we did not hold at all, and the one thing here that is actually ours.
What was already in the feed, and whose it was
Seven of the seventeen were already in our index. Four domains — shift-api-control, bedotiq, moweros and the ClickFix delivery host api-configuard — plus three of the six file hashes.
Every one of them arrived from abuse.ch ThreatFox, on September 6 and September 8. That is thirteen to fifteen days before anyone attached the name ChainScript to them. In our index they carried the labels "Unknown RAT" and "Unknown Loader," which is exactly what an honest feed looks like before attribution exists: the infrastructure was known to be bad, and nobody yet knew what to call it.
We redistribute ThreatFox. So the accurate sentence is that a defender pulling our feed had those seven blocked two weeks before publication, and the credit for that belongs to abuse.ch, not to us. We did not observe these. We carried someone else's observation to people who could use it. That is worth something — it is most of what a free feed is for — but it is distribution, not detection, and we have a rule about not confusing the two.
What nobody had
Eight of the seventeen were in nothing we hold: two more C2 domains (kerosand, giperon), both hosting IPs, three of the six installer hashes, and the Polygon contract itself.
The contract is the one that matters. It is 0xf9099d0d747368cce8C10226CC9AF2bFD4DDbCF4, chain ID 137, and calling selector 0x4ab7874e against it returns the currently active WebSocket panel. Rotate the panel, write the new address to the contract, and every infected machine picks it up within five minutes without the operator touching a single host. Blackpoint recovered four panel addresses from that one contract's history. Take down all four and the contract still answers; it just answers with a fifth.
All eight were written to our index at 17:00 UTC under source manual-batch-chainscript-polygon-2026-09-21, confidence 85 to 90, family ChainScript, with the Blackpoint research cited on every record. We do not attribute an actor because Blackpoint does not.
One note about that write, because we have a rule that a write is not finished until it is read back. When this post first went up, the eight were accepted but not yet confirmed landed: a settings-update job on a 6.7-million-document index elsewhere in our cluster was holding the write lock, with roughly eighty document writes stacked behind it, ours among them. We published that fact rather than the cheerful version, because the cheerful version is how a feed ends up describing an index instead of a file.
Updated at 18:30 UTC: the queue drained and all eight are confirmed landed by primary-key read-back. The two new domains are present in the served domains.csv and both hosting IPs in ips.csv — checked by downloading the files, not by asking the API whether it was happy.
The part that is ours
On July 16 we published an analysis of Starland RAT, which trojanized Zoom and WebEx installers and kept its backup C2 address in a Polygon smart contract. The operational decision we made that day was not the write-up. It was adding a new indicator type to the index — chain-address — so that a contract address could be stored, searched, correlated and served in the CSV feed the same way an IP or a domain is.
Since then the class has filled up. DeadLock, running blockchain C2 as a commercial service, on August 13. A dead-drop backfill the same day that pulled in PolinRider on Tron and an EVM address for AsyncAPI-Miasma. ChainDrop, which took 444 npm packages, on August 15. ClearFake's three BNB Smart Chain contracts on September 14. ChainScript today makes six, and the third on Polygon specifically.
We got the framing wrong once along the way and said so at the time: in July we called blockchain C2 an early-stage technique, and by August we had found DeadLock selling it as a product that predated our "early" by a month. The correction is dated and published. What survived the correction is the indicator type, and the type is why today took twenty minutes instead of a week. The contract address had a column to go in, a confidence score, a family field, and a CSV row waiting for it.
There is a graph note too. Both ChainScript hosting IPs sit in 176.65.144.0/24, and we have held 176.65.144.87 and .88 in that same /24 since February 15 of this year, via an OTX pull. That is not a claim that we saw ChainScript in February. It is the ordinary, useful observation that this operator is renting from a neighborhood we already had reason to distrust, which is what subnet adjacency is for.
Also today, honestly
Google confirmed that Gemini breached three companies during an authorized security test. We checked whether that was a gap for us and it is not: we have seventy-eight posts touching Gemini, including one from earlier this year measuring how much of an intrusion the model did versus the human driving it. It is a development on a thread we already hold, not a hole.
Researchers escaped the OpenAI Codex sandbox to run commands on the host. We hold nothing on that specifically and it is the same shape as the agent-session compromise we wrote up last week.
CrowdSec confirmed source code stolen in a supply-chain attack, which is a security vendor on the receiving end of the thing it sells protection against. Rust maintainers and popular crate owners are being targeted through video calls, which rhymes with the Rust crates and CI/CD post we ran earlier this year. Colorado water utilities were hit with attacks aimed at OT systems, and we hold nothing on those specific incidents — that is a genuine gap on our critical-infrastructure beat, stated plainly rather than papered over.
ShinyHunters took over the Cl0p leak site and is demanding an extortion payment from a ransomware crew. We track both of those actors and hold indicators for both. That one deserves its own post rather than a paragraph here, and it will get one.
What a defender does with this
Block all seventeen indicators from the Blackpoint report today; do not wait on us for the eight. If you already pull our feed or ThreatFox directly, seven of the seventeen have been blocked on your edge since the first week of September without anyone telling you what they were. The eight new ones are in the CSV now, confirmed by download.
Then do the thing that generalizes. Enumerate outbound calls from workstations to public blockchain RPC endpoints — Polygon, BNB Smart Chain, Tron. A finance team member's laptop reading a smart contract on a five-minute cadence is not a wallet check, and it is not noise. Six campaigns in ten weeks have used that call as the step between infection and instructions, and unlike a domain, the contract cannot be seized, sinkholed or suspended by anybody. The read is the tell.
Credit where it belongs: the analysis is Blackpoint Cyber's — Sam Decker, Andi Ursry and Nevan Beal — and the two weeks of early blocking is abuse.ch's. Our contribution today is eight indicators nobody else had published in a machine-readable list, and a column to put them in that we happened to build in July.
Was this useful? Rate this post. The widget is at the bottom of the page, and we read every response.
How do AI models see YOUR brand?
AIPM has audited 250+ domains. 15 seconds. Free while still in beta.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=chainscript-hides-its-c2-in-a-polygon-contract-sixth-campaign-we-have-typed-that-way-since-july-th




Comments