Macfinger ClickFix campaign, (Tue, Sep 22nd)

2026-09-23T19:23:42Z•10309d2e3f0137e1ac1ff6f1ddef33d1772598bac185af7092797bba335ebe04
ClickFixHTTP QUERYLausivLoaderMacfingerPNG steganographySANS ISCTerminalFixmalspammultistage malwarephishingreverse tunnelsocial engineering

What happened

SANS Internet Storm Center entries from September 17–23, 2026 cover multiple security topics, including the Macfinger ClickFix phishing campaign, LausivLoader malware delivery and staged data transfer, and TerminalFix activity using PNG steganography and reverse tunneling. The feed also includes HTTP QUERY method analysis and routine Stormcast episodes. The malware and phishing reports indicate active social-engineering and multistage intrusion techniques, but the supplied metadata contains no specific indicators or confirmed CVE references.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
10309d2e3f0137e1ac1ff6f1ddef33d1772598bac185af7092797bba335ebe04
Enrichment time
2026-09-23T19:23:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.