Red Hat ClickFix: Threat Intelligence Study
Longitudinal study of a four-stage macOS ClickFix chain, Polygon dead-drop resolver, 160-second initial containment interval and sixteen dated observations.
Red Hat ClickFix: Threat Intelligence Study
Status
- Incident response and forensic analysis: completed for the documented scope.
- Longitudinal observation corpus: sixteen records from 2 to 10 July 2026.
- Current publication stage: repository and editorial preparation.
Summary
On 2026-06-25, an external article link in the public
redhat-developer/lsp4ij README led through idetools.dev to a ClickFix page
that copied a command to the clipboard and instructed the user to execute it in
Terminal. The recovered four-stage macOS chain used user-scoped persistence,
AppleScript credential phishing, modular collection and a Polygon dead-drop
resolver for C2 hostname updates.
The identified process and user-scoped persistence path were contained within 160 seconds of the first recorded alert. The versioned observation corpus later recorded three successive contract-returned hostnames.
Pages in Wikifita
- clickfix-handoff — Executive overview
- clickfix-attack-chain — Domain hijack → ClickFix → persistence → fake PAM
- clickfix-bddr — Blockchain Dead-Drop Resolver
- clickfix-c2-bot — Bot polling, command dispatch
- clickfix-stealers — smodule + lmodule (60 wallet targets)
- clickfix-iocs — IOC inventory, MITRE ATT&CK, detection
- clickfix-incident-response — 160s IR, AI-assisted
- clickfix-infrastructure — Dated infrastructure observations and hypothesis evaluation
Repository
~/workdir/co-fita/redhat-clickfix-report/
Key Metrics
- 160 seconds: first recorded alert to initial containment verification
- 20 MITRE ATT&CK techniques mapped
- 60 crypto wallet extensions targeted
- 3 C2 domain rotations observed
- 4 prospective statements registered before the final observations
- 16 monitoring records (2 to 10 July 2026)