One URL, Three Different Tricks, (Thu, Sep 24th)

2026-09-25T01:23:41Z•40d9dbb87e9d09ced63fd6c849854c749bd237e94354e87761face215b6f5770
ClickFixHTTP QUERYLausivLoaderMacfingerPNG steganographySANS ISCTerminalFixevasionmalspammulti-stage malwarephishingreverse tunnel

What happened

SANS Internet Storm Center entries describe phishing links crafted to evade basic security controls, the Macfinger ClickFix campaign, LausivLoader malware delivered through malspam and staged payloads, and TerminalFix activity using PNG steganography and reverse tunneling. The feed also discusses the emerging HTTP QUERY method and related protocol behavior. No specific CVEs or exploit identifiers are provided.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
40d9dbb87e9d09ced63fd6c849854c749bd237e94354e87761face215b6f5770
Enrichment time
2026-09-25T01:23:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.