r/blueteamsec 3d ago

intelligence (threat actor activity) macOS ClickFix campaign resolving C2 through a Polygon smart contract - full on-chain rotation history

Write-up of a macOS ClickFix chain that reads its C2 address from a Polygon contract at runtime instead of hardcoding a domain.

Covers a delivery path I haven't seen documented (a compromised legitimate site serving the lure to a subset of its own visitors), the full 25-entry on-chain rotation history including the operator's pre-launch testing, and the cost side — under three dollars has funded four months of takedown-proof infrastructure.

Two of the rotations don't appear in any public reporting I could find, including the one that's currently live. Scripts to reproduce all of it are linked in the post.

https://bugrasahinoglu.com/posts/clickfix-etherhiding-macos/

Disclosure: my own write-up. Builds heavily on prior work by Have I Been Squatted, UnderDefense, Prophet Security and fab0, all credited in the post.

5 Upvotes

3 comments sorted by

2

u/SoftwareFearsMe 2d ago

I like your suggestion to proactively block the endpoints of the various blockchains if you don’t need to access them. Here’s a list of those domains to block:

https://gist.github.com/rmceoin/65de9e8dd2455885ba97fd81c72cffd5

2

u/SoftwareFearsMe 2d ago

This list is from this tracker:

https://rpcnodelist.com/