WikifitaGitHub live67e8de5
projeto · memorias/projetos/redhat_clickfix_report/README

Red Hat ClickFix: Threat Intelligence Study

Longitudinal study of a four-stage macOS ClickFix chain, Polygon dead-drop resolver, 160-second initial containment interval and sixteen dated observations.

Baixar raw

Red Hat ClickFix: Threat Intelligence Study

Status

  • Incident response and forensic analysis: completed for the documented scope.
  • Longitudinal observation corpus: sixteen records from 2 to 10 July 2026.
  • Current publication stage: repository and editorial preparation.

Summary

On 2026-06-25, an external article link in the public redhat-developer/lsp4ij README led through idetools.dev to a ClickFix page that copied a command to the clipboard and instructed the user to execute it in Terminal. The recovered four-stage macOS chain used user-scoped persistence, AppleScript credential phishing, modular collection and a Polygon dead-drop resolver for C2 hostname updates.

The identified process and user-scoped persistence path were contained within 160 seconds of the first recorded alert. The versioned observation corpus later recorded three successive contract-returned hostnames.

Pages in Wikifita

Repository

~/workdir/co-fita/redhat-clickfix-report/

Key Metrics

  • 160 seconds: first recorded alert to initial containment verification
  • 20 MITRE ATT&CK techniques mapped
  • 60 crypto wallet extensions targeted
  • 3 C2 domain rotations observed
  • 4 prospective statements registered before the final observations
  • 16 monitoring records (2 to 10 July 2026)