Macfinger ClickFix campaign, (Tue, Sep 22nd)
2026-09-24T01:23:41Z•409f216cc63c01e0c90795f4afd4af972a9203b0d35cd9b16f6c1053bee9d0a8
ClickFixHTTP QUERYLausivLoaderMacfingerPNG steganographySANS ISCTerminalFixmalspammultistage malwarephishingreverse tunnelthreat intelligence
What happened
SANS Internet Storm Center RSS entries covering September 17–23, 2026. Security-relevant topics include Macfinger and TerminalFix ClickFix campaigns, PNG steganography used to deliver multistage malware and reverse tunnels, LausivLoader malware staging via malspam and impersonation, and discussion of the new HTTP QUERY method. The feed contains no explicit CVE identifiers.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 409f216cc63c01e0c90795f4afd4af972a9203b0d35cd9b16f6c1053bee9d0a8
- Enrichment time
- 2026-09-24T01:23:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.