<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Campaign-Analysis on CuraSec</title><link>https://curasec.metacog.co.kr/tags/campaign-analysis/</link><description>Recent content in Campaign-Analysis on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 25 Sep 2026 15:49:12 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/campaign-analysis/index.xml" rel="self" type="application/rss+xml"/><item><title>SANS ISC: Malware Analysis of Macfinger ClickFix Campaign</title><link>https://curasec.metacog.co.kr/insights/2026-09-25-a-closer-look-at-malware-from-the-macfinger-clickfix-campaig/</link><pubDate>Fri, 25 Sep 2026 15:49:12 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-25-a-closer-look-at-malware-from-the-macfinger-clickfix-campaig/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> ClickFix campaigns abuse clipboard to trick users into running malicious commands — relevant to teams managing macOS endpoints. Summary is too thin to extract specifics; read the full SANS diary to check for any IOCs or configuration hardening points applicable to your Mac fleet.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> ClickFix is a technique with detectable behavioral surface (clipboard abuse leading to terminal/shell execution). Review the full SANS ISC diary for published IOCs and consider tuning EDR behavioral detections to catch suspicious clipboard-sourced command execution on macOS endpoints.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>