Bottom line: Threat actors are using compromised ClickFix software to deploy a previously undocumented RAT, ChainScript, to steal sensitive data.
What's happening: Threat actors compromised ClickFix to lure in users with legitimate-looking updates, while ChainScript uses Polygon to rotate its C2 servers and evade detection.
What to do: Security leaders should ensure their security teams are aware of the ChainScript RAT and its use of Polygon C2 infrastructure, and implement additional security measures to prevent similar attacks.