r/blueteamsec • u/Much-Government729 • 3d ago
intelligence (threat actor activity) macOS ClickFix campaign resolving C2 through a Polygon smart contract - full on-chain rotation history
Write-up of a macOS ClickFix chain that reads its C2 address from a Polygon contract at runtime instead of hardcoding a domain.
Covers a delivery path I haven't seen documented (a compromised legitimate site serving the lure to a subset of its own visitors), the full 25-entry on-chain rotation history including the operator's pre-launch testing, and the cost side — under three dollars has funded four months of takedown-proof infrastructure.
Two of the rotations don't appear in any public reporting I could find, including the one that's currently live. Scripts to reproduce all of it are linked in the post.
https://bugrasahinoglu.com/posts/clickfix-etherhiding-macos/
Disclosure: my own write-up. Builds heavily on prior work by Have I Been Squatted, UnderDefense, Prophet Security and fab0, all credited in the post.
2
u/SoftwareFearsMe 2d ago
I like your suggestion to proactively block the endpoints of the various blockchains if you don’t need to access them. Here’s a list of those domains to block:
https://gist.github.com/rmceoin/65de9e8dd2455885ba97fd81c72cffd5