Podcast Detail

SANS Stormcast Thursday, September 24th, 2026: Macfinger ClickFix; Malicious Terraform; MikroTik and F5 Big IP Vulnerability Details

If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://traffic.libsyn.com/securitypodcast/10108.mp3

Podcast Logo
Macfinger ClickFix; Malicious Terraform; MikroTik and F5 Big IP Vulnerability Details
00:00

My Next Class

Click HERE to learn more about classes Johannes is teaching for SANS

Podcast Transcript

 Hello and welcome to the Thursday, September 24th, 2026
 edition of the SANS Internet Storm Center's Stormcast. My
 name is Johannes Ullrich, recording today from Las
 Vegas, Nevada. And this episode is brought to you by
 the SANS.edu Graduate Certificate Program in Cloud
 Security. Well, to start out with, we have a diary by Brad
 today, again, doing some interesting malware analysis
 using network traffic. This particular sample is part of a
 click fix campaign that Brad calls MacFinger. The name
 comes from, well, this particular campaign targeting
 Macs and using some fingerprinting in order to
 figure out if they are actually targeting here or are
 connected to a Mac. Now, the click fix campaign itself uses
 a number of compromised sites, nothing really all that
 special on this end. But then it includes the actual capture
 that implements the click fix campaign again from legitimate
 but compromised sites, a trick that attackers like to use in
 order to bypass some reputation filters that
 defenders may have deployed. Once the victim is falling for
 the click fix campaign and copy pasting the script into
 the terminal, the exploitation starts and ends up with an
 info stealer in the end. Aikido published a blog post
 detailing a very specific supply chain attack. They call
 it the Craft Algo campaign. And the first thing that's
 odd, different about this campaign is that it actually
 takes advantage of malicious Terraform providers. Now,
 these Terraform providers will load Go modules that implement
 a remote admin tool, but they'll only load these Go
 modules if there is a very specific Docker container name
 and network ID present on the system. Only the SHA-56 hash
 is included in the malware, so it's unclear what this exact
 name is. But Aikido assumes that this attack was supposed
 to target a very specific organization. Now, why would
 someone install these malicious Terraform providers?
 The reason here is typosquatting that they mimic
 very popular Docker-related Terraform providers. If you're
 interested in more details, please refer to the Aikido
 blog. And the Polish cert has published a detailed write-up
 regarding two vulnerabilities that MicroTik recently patched
 in its router OS. If you remember, I talked about this
 when it was first reported that there was a vulnerability
 in MicroTik's router OS, specifically in the SH daemon
 that is delivered as part of a router OS, that allowed for an
 authentication bypass via SH and complete compromise of the
 router. Now, MicroTik did release patches, but no
 details about what exactly happened. The Polish cert is
 now filling this gap and they discovered two distinct
 vulnerabilities. One is a re -key during the authentication
 process with the SH server that bypasses authentication.
 The other part, and that's actually sort of the neatest
 part here I find in some ways, is in order to exploit this
 vulnerability, a username of dash two or minus two was
 used. Well, it turns out that that actually redirects the
 input to the SH daemon from the client. So that's another
 part here of the authentication bypass.
 Interesting write-up and definitely if you're running
 MicroTik, make sure you're up to date. Remember, this was
 also an SH daemon that's unique to MicroTik. So this is
 not a standard SH implementation like DropBear
 or OpenSH that they're deploying as part of a router
 OS. And yesterday I talked about an exploited
 vulnerability that was patched in F5's Big-IP devices. Well,
 today, we got the, as usual, quite entertaining write-up
 from WatchTowr about this vulnerability. The problem is,
 well, in hindsight, relatively straightforward. It's a buffer
 overflow in the auth header. You need a bit more than 16
 kilobytes of data in order to trigger this buffer overflow.
 And WatchTowr, in reversing the patch released, basically
 found that they had no length check on that value at all.
 And the patch was essentially just adding this length check
 to the value before it's being copied into the buffer. The
 auth header can be quite large sometimes depending on what
 kind of tokens you use. So 16 kilobytes may not be that
 outrageous last actually a little bit longer than 16
 kilobytes. But anyway, no matter the link, you still
 have to check that you're not copying any more than that
 into the respective buffer. Well, and that's it for today.
 So thanks again for listening, for subscribing, for liking.
 And yeah, also, if you have a minute, then please leave a
 good comment on your favorite podcast platform, like Apple
 Podcasts or whatever you're using to listen to this
 podcast. Thanks and talk to you again tomorrow. Bye. Bye.