ThreatPaper
False

Blockchain smart-contract C2 discovery is unique to ChainScript

Assessment

ChainScript's most distinctive feature is that it reads a Polygon smart contract to locate its active WebSocket C2 infrastructure, an EtherHiding-style technique that separates C2 discovery from the implant and resists takedown. But it is not novel to ChainScript: Blackpoint's own analysis states the malware uses this approach 'like many malware families observed in recent months,' and EtherHiding — abusing blockchain smart contracts as a resilient dead-drop resolver for C2 — has been an established and increasingly common technique since it was first popularised in 2023. A reader who takes coverage of ChainScript's Polygon-based C2 to mean the RAT pioneered blockchain C2 would be crediting it with a technique it merely adopted from a broader trend the researchers explicitly flag.

Where this claim appeared

Blackpoint APG (via The Hacker News) · 2026-09-21

https://thehackernews.com/2026/09/clickfix-lures-deploy-chainscript-rat.html

What “False” means

Contradicted by primary sources. Reserved for claims checked directly against the authoritative record — an advisory that does not exist, a catalogue that does not list the entry, a directive that says something other than what is reported.

1 of 5 · rating scale

Assessed in

ChainScript RAT: a ClickFix-delivered trojan that hides its C2 pointer in a Polygon smart contract

Think this assessment is wrong? Report an error.