Blockchain smart-contract C2 discovery is unique to ChainScript
Assessment
ChainScript's most distinctive feature is that it reads a Polygon smart contract to locate its active WebSocket C2 infrastructure, an EtherHiding-style technique that separates C2 discovery from the implant and resists takedown. But it is not novel to ChainScript: Blackpoint's own analysis states the malware uses this approach 'like many malware families observed in recent months,' and EtherHiding — abusing blockchain smart contracts as a resilient dead-drop resolver for C2 — has been an established and increasingly common technique since it was first popularised in 2023. A reader who takes coverage of ChainScript's Polygon-based C2 to mean the RAT pioneered blockchain C2 would be crediting it with a technique it merely adopted from a broader trend the researchers explicitly flag.
Where this claim appeared
Blackpoint APG (via The Hacker News) · 2026-09-21
https://thehackernews.com/2026/09/clickfix-lures-deploy-chainscript-rat.htmlWhat “False” means
Contradicted by primary sources. Reserved for claims checked directly against the authoritative record — an advisory that does not exist, a catalogue that does not list the entry, a directive that says something other than what is reported.
1 of 5 · rating scale
Assessed in
ChainScript RAT: a ClickFix-delivered trojan that hides its C2 pointer in a Polygon smart contractThink this assessment is wrong? Report an error.