Go back

Diversiedades - Episodio 0

from Diversiedades

6m 40s

Diversiedades - Episodio 0

A recent analysis of the Macfinger ClickFix campaign reveals that the malware payload is likely not the original Amos stealer, but a derivative using web sockets for data exfiltration and operating in separate ARM and x86_64 versions. This highlights evolving evasion tactics in macOS-based attacks. Simultaneously, multiple critical vulnerabilities in Citrix Netscaler ADC and Gateway—particularly two remote code execution flaws—have been actively exploited, prompting urgent patching. These vulnerabilities include HTTP request smuggling and TCP sequence number prediction, with CVSS scores up to 8.8, emphasizing their severity. A separate incident involves Kite Works advising customers to shut down servers for six hours on Saturday to mitigate a targeted attack, though the long-term solution or patch deployment remains unclear. Additionally, Shiny Hunters continues targeting Oracle PeopleSoft, now bypassing web application firewalls by modifying URLs through simple character changes—an exploit that circumvents basic WAF protections. The situation underscores the importance of timely patching, vendor communication, and understanding limitations in security tools. Organizations relying on Citrix or secure messaging platforms must act swiftly to avoid service outages or data breaches.

Transcription

881 Words, 5238 Characters

English
Hello and welcome to the Monday, September 28th, 2026 edition of the "Sans and It's Storms and It's Stormcast." My name is Johannes, always recorded from Jacksonville, Florida. And this episode is brought to you by the "Sans.edu Undercratted Certificate Program" in Cybersecurity Fundamentals. On Friday, Brad posted a diary that's a follow-up to a diary he actually posted a couple days earlier. That diary dealt with the Macfinger ClickFix campaign and back then, Brad identified the eventual payload being installed as the atomic macOS dealer, or Amos. Well it turns out that this wasn't quite right or at least Brad isn't certain. If it was this particular stealer or maybe a new variant of it or maybe something somewhat different, that sort of took some inspirations from Amos's stealer. Couple of differences here that Brad points out is that this stealer for example does use a web socket in order to exfiltrate data. Another sort of little odd thing about this stealer is that it comes in two versions. It comes in the ARM and the X8664 version. It does not come as a unified binary that you could use in Mac OS in order to essentially support both architectures. The attacker then also exfiltrates data via post requests, but the bulk of the command control appears to be happening via the web socket connection, which may be done to evade some data leakage protection products. Well, if you need more details, indicators of compromise specifically to the infos stealer that was detected here, please refer to Brad's diary. One of the big stories this weekend was certainly the exploitation of two unpatched vulnerabilities in Citrix Netscaler ADC and Citrix Netscaler Gateway. This originally sort of emerged as sort of a rumor on Friday, apparently an information security agency in the Netherlands did advise its constituency to turn off any Citrix Netscalers on Sunday. Citrix then released a patch fixing a total of eight vulnerabilities and stating that two of these vulnerabilities, both remote code execution vulnerabilities, are currently being exploited. The other six vulnerabilities aren't really all that harmless either. So if you have, for example, an HTTP request smuggling, which then could be used to essentially attack systems behind Citrix Netscaler, also feature policy bypass due to improper HTTP URL based expression usage, this is the lowest one according to CVSS score with 7.0, but let me have a few 8.8 ones, including one that's sort of interesting here. Yeah, there is an TCP initial sequence number prediction of vulnerability. Now in this case, you need to have the TCP configuration enabled in Netscaler ADC or Netscaler Gateway again. So get these patched, get these patched quickly. I don't want to recommend anybody just turn off Netscaler just because I know that these are usually systems that protect a number of different applications alike. So disabling them is probably going to cause some significant disruption of your business. But on the other hand, Ransomber is going to disrupt your business too. So carefully, way off the Pro and Concier and yes, definitely this is a patch that you probably want to rush out if you're using Citrix Netscaler. And talking about shutting down servers, kite works urged its customers to shut down servers on Saturday. So yes, this news is coming a bit late, but if you didn't get the message, you may want to check in with kite works to see what exactly happened there because I couldn't really find a lot of details. The main source here is hyz.de, the German IT news outlet, they got a hold of an email that kite works send to customers and yes, it specified a very specific six hour window on Saturday where you should down, should shut down your kite works server. Again, this is secure messaging platform. So certainly a critical piece of IT infrastructure. Kite works did state to hyz that this was due to a Saturday attack. Now, I'm not sure how shutting it down for six hours is supposed to help here, whether or not there was a patch deployed afterwards. I didn't found any indication for this, but again, this may have just been communicated to customers directly and not via any public channels. So please double check with kite works. And Manian is reporting that shiny hunters continues to target oracle people soft and they're targeting June, 2026 vulnerability, but they are now bypassing replication firewalls. So remember, if you're using a web application firewall to protect yourself from exploitation, it's usually time limited protection factors will find base around it. And the work around here appears to be pretty straightforward and simple, where they're just yorling coding one of the letters in the URL. Something that actually most web application firewalls that I'm aware of should be able to handle, but apparently there is sufficient number of firewalls that don't and that leads sort of to a renewed search of exploitation of people soft by shiny hunters. Well, and this is it for today. So thanks for listening. Thanks for liking. Thanks for recommending this podcast as always, special thanks for leaving good comments on your favorite podcast platform. And that's it for today and talk to you again tomorrow. Bye.

Podcast Summary

Key Points:

  1. Brad revises his earlier identification of the Macfinger ClickFix campaign payload, noting it is likely a variant or inspired by the Amos stealer but with key differences.
  2. The malware uses web sockets for data exfiltration and operates in separate ARM and x86_64 versions, not as a unified binary, to support different architectures.
  3. Two critical remote code execution vulnerabilities in Citrix Netscaler ADC and Gateway have been actively exploited, prompting urgent patching.
  4. The vulnerabilities include HTTP request smuggling, URL expression policy bypass, and TCP initial sequence number prediction, with CVSS scores ranging from 7.0 to 8.8.
  5. Kite Works advised customers to shut down servers for six hours on a Saturday due to a targeted attack, though the effectiveness and follow-up patch remain unclear.
  6. Shiny Hunters is bypassing web application firewalls by altering URLs through simple character obfuscation, exploiting limited firewall detection capabilities.
  7. Oracle PeopleSoft remains a target, with attackers using this method to circumvent replication firewalls despite existing protections.
  8. Security professionals are urged to patch Citrix systems quickly and verify server shutdown instructions directly with vendors due to potential business disruption.

Summary:

A recent analysis of the Macfinger ClickFix campaign reveals that the malware payload is likely not the original Amos stealer, but a derivative using web sockets for data exfiltration and operating in separate ARM and x86_64 versions. This highlights evolving evasion tactics in macOS-based attacks. Simultaneously, multiple critical vulnerabilities in Citrix Netscaler ADC and Gateway—particularly two remote code execution flaws—have been actively exploited, prompting urgent patching.

8, emphasizing their severity. A separate incident involves Kite Works advising customers to shut down servers for six hours on Saturday to mitigate a targeted attack, though the long-term solution or patch deployment remains unclear. Additionally, Shiny Hunters continues targeting Oracle PeopleSoft, now bypassing web application firewalls by modifying URLs through simple character changes—an exploit that circumvents basic WAF protections.

The situation underscores the importance of timely patching, vendor communication, and understanding limitations in security tools. Organizations relying on Citrix or secure messaging platforms must act swiftly to avoid service outages or data breaches.

FAQs

The Macfinger ClickFix campaign involves a stealer that initially appeared to use the Atomic macOS Stealer (Amos), but Brad has since questioned this. The actual payload appears to be a variant inspired by Amos, using web sockets for data exfiltration and available in separate ARM and x86_64 versions, not as a unified binary.

The stealer uses web sockets for command and control, which helps it evade data leakage protection products that may detect or block traditional HTTP-based data exfiltration.

Eight vulnerabilities were discovered, including two remote code execution flaws. Others include HTTP request smuggling, URL-based policy bypass, and a TCP initial sequence number prediction vulnerability, all of which can be exploited to attack systems behind the gateway.

Disabling Citrix Netscaler is not recommended as these systems typically protect critical applications. Patching is advised instead, as shutting them down could cause significant business disruption.

Kite Works advised customers to shut down their servers for six hours on a specific Saturday due to a targeted attack. This directive was communicated directly via email and not publicly disclosed beforehand.

No public information confirms a patch was deployed after the attack. The shutdown was likely a temporary mitigation, and no evidence suggests a post-attack fix was released.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.