Macfinger ClickFix campaign, (Tue, Sep 22nd)
2026-09-23T01:23:41Z•8a2d5bc1533d8cee47051d1da882dddb30130dc849fc74463acc5b649efd585a
ClickFixHTTP-QUERYLausivLoaderMacfingerPNG-steganographySANS-ISCTerminalFixdefense-evasionhospitality-applicationsmalspamphishingreverse-tunnelstaged-malwareweb-scanning
What happened
SANS Internet Storm Center feed containing multiple security diary entries, including a Macfinger ClickFix campaign, LausivLoader malspam and staged malware delivery, TerminalFix reverse-tunnel activity using PNG steganography, a newly described HTTP QUERY method, and scans targeting hospitality applications. The entries describe active phishing, malware, defense-evasion, and reconnaissance activity, but provide insufficient detail to attribute a specific CVE.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 8a2d5bc1533d8cee47051d1da882dddb30130dc849fc74463acc5b649efd585a
- Enrichment time
- 2026-09-23T01:23:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.