ClickFix turns the user into the execution mechanism

Ullrich opens with the Macfinger campaign documented by SANS. Compromised websites present a fake verification flow that fingerprints macOS visitors and instructs them to paste a command into Terminal. The action leads to an information stealer.

The useful detection surface is the chain, not the fake CAPTCHA alone: browser navigation, clipboard use, Terminal launch, shell or script execution, payload retrieval, persistence, credential access, and outbound traffic. Training should make one rule memorable: a website should never need a pasted terminal command to prove a visitor is human.

Infrastructure code can hide a targeted dependency

The episode next covers Aikido’s report of Graphalgo-linked malware in typosquatted Terraform providers and Go modules. The researchers identified two malicious providers—gocommunity-io/dockerd and kreuzwenker/docker—and two Go modules, gocommunity.io/orderedbtree and gogets.dev/btreex.

Aikido says the payload checks for a specific Docker container name and network identifier before activating, which may indicate a targeted operation. That remains the researcher’s assessment; the public hash does not reveal the target. Defenders should search dependency records and build logs before assuming installation means successful payload execution.

Two edge cases, two different failure modes

TopicWhat the episode highlightsDefender check
MikroTik RouterOSCERT Polska describes two flaws in MikroTik’s custom SSH implementation, including authentication-state handling and special username parsing.Verify the fixed RouterOS release, restrict management reachability, and review authentication and configuration changes.
F5 BIG-IP APMTechnical analysis traces CVE-2026-94127 to an oversized authorization value copied without the necessary length check.Identify APM OAuth authorization servers, preserve evidence, and install the vendor’s exact engineering hotfix.

Threat Field Notes assessment

These are four separate stories. Their common operational theme is misplaced trust: in a verification prompt, a package name, an authentication state, or an authorization header. Controls should validate the action and boundary, not only the wrapper.

Four checks to carry into the week

  1. 1

    Hunt for browser-to-terminal execution. Correlate browser activity with Terminal, shell, AppleScript, downloader, credential-access, and persistence events on macOS. Preserve the command and downloaded content.

  2. 2

    Search infrastructure dependencies. Look for the named Terraform providers and Go modules in manifests, lockfiles, module caches, CI logs, and artifact inventories. Investigate activation conditions separately from presence.

  3. 3

    Verify edge-appliance configuration. Confirm MikroTik and F5 versions, management exposure, enabled roles, and installed hotfixes from the running system rather than a procurement inventory.

  4. 4

    Protect evidence before restarting. For appliances under active-exploitation pressure, retain external telemetry and follow vendor collection guidance before changes erase volatile state.

How this brief was prepared

Johannes B. Ullrich hosts the 24 September SANS Stormcast. Threat Field Notes used the episode and its linked research to identify the main topics, then wrote this original defender synthesis. It is not a transcript and does not merge the four stories into one campaign.