Macfinger ClickFix campaign, (Tue, Sep 22nd)
2026-09-23T19:23:42Z•10309d2e3f0137e1ac1ff6f1ddef33d1772598bac185af7092797bba335ebe04
ClickFixHTTP QUERYLausivLoaderMacfingerPNG steganographySANS ISCTerminalFixmalspammultistage malwarephishingreverse tunnelsocial engineering
What happened
SANS Internet Storm Center entries from September 17–23, 2026 cover multiple security topics, including the Macfinger ClickFix phishing campaign, LausivLoader malware delivery and staged data transfer, and TerminalFix activity using PNG steganography and reverse tunneling. The feed also includes HTTP QUERY method analysis and routine Stormcast episodes. The malware and phishing reports indicate active social-engineering and multistage intrusion techniques, but the supplied metadata contains no specific indicators or confirmed CVE references.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 10309d2e3f0137e1ac1ff6f1ddef33d1772598bac185af7092797bba335ebe04
- Enrichment time
- 2026-09-23T19:23:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.