{"id":244322,"date":"2026-09-21T21:28:18","date_gmt":"2026-09-22T02:28:18","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/09\/clickfix-lures-deploy-chainscript-rat-using-polygon-to-rotate-c2-infrastructure"},"modified":"2026-09-21T21:28:18","modified_gmt":"2026-09-22T02:28:18","slug":"clickfix-lures-deploy-chainscript-rat-using-polygon-to-rotate-c2-infrastructure","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/09\/clickfix-lures-deploy-chainscript-rat-using-polygon-to-rotate-c2-infrastructure","title":{"rendered":"ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/clickfix-lures-deploy-chainscript-rat-using-polygon-to-rotate-c2-infrastructure.jpg\"><\/a><\/p>\n<p>The cybersecurity company described the activity as <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2026\/05\/fake-claude-search-results-lure-mac-users-into-clickfix-attack\" target=\"_blank\">part<\/a> of a <a href=\"https:\/\/pushsecurity.com\/blog\/llmshare-malvertising-campaign\" target=\"_blank\">broader pattern<\/a> of <a href=\"https:\/\/www.trendmicro.com\/en\/research\/26\/f\/claudeai-shared-chat-abused-in-malvertising.html\" target=\"_blank\">attacks<\/a> that employ trusted services and large language model (LLM) shared chats to serve fake installation instructions, while bypassing browser warnings, URL inspection, and Safe Browsing heuristics.<\/p>\n<p>In a report published last month, Microsoft said it observed a macOS ClickFix campaign propagating MacSync and Atomic Stealer using a cluster of no less than 250 look-alike domains.<\/p>\n<p>\u201cThe campaign evolved from broadly serving ClickFix lures to using a server-side browser-fingerprinting gate that shows the lure primarily to visitors whose environment appears consistent with a genuine macOS browser,\u201d it <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/08\/05\/macos-clickfix-campaign-learned-hide\/\" target=\"_blank\">said<\/a>. \u201cThis cloaking limits visibility for crawlers, sandboxes, and some automated analysis workflows.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The cybersecurity company described the activity as part of a broader pattern of attacks that employ trusted services and large language model (LLM) shared chats to serve fake installation instructions, while bypassing browser warnings, URL inspection, and Safe Browsing heuristics. In a report published last month, Microsoft said it observed a macOS ClickFix campaign propagating [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34,6],"tags":[],"class_list":["post-244322","post","type-post","status-publish","format-standard","hentry","category-cybercrime-malcode","category-robotics-ai"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/244322","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=244322"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/244322\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=244322"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=244322"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=244322"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}