SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefFriday, July 17, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY ClickLock macOS Malware Kills Apps For Passwords | CRITICAL |
|
5 C2 IPs | 49 OTX IOCs | 37 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is highlighted by the emergence of ClickLock, an aggressive macOS infostealer that forces credential disclosure by repeatedly terminating user processes, alongside modular threats like TELEPUZ and ACR Stealer spreading via ClickFix social engineering lures. Additionally, critical authentication bypass flaws in n8n Enterprise and newly discovered AI data injection techniques highlight growing risks to automated workflows and AI agents. Meanwhile, state-sponsored activity remains high with Sandworm deploying PowerShell-based CAPTCHA tricks and China-linked actors resurfacing with the Daxin and Stupig backdoors. |
|
■ CRITICAL STORIES New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password This highly aggressive infostealer bypasses traditional macOS security by terminating visible processes on a tight loop, effectively holding the user's system hostage until they input their login credentials into a fake system dialog. |
n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer Enterprise instances of the n8n workflow automation platform configured with multiple token issuers are vulnerable to complete account takeover because the platform improperly matches JWTs using only the 'sub' claim while ignoring the 'iss' claim. |
Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor A highly advanced, kernel-mode backdoor linked to Chinese state-sponsored actors has resurfaced in Taiwan's manufacturing sector after four years of silence, accompanied by a new, previously undocumented pre-login SYSTEM backdoor named Stupig. |
Coca-Cola says Fairlife ransomware attack halts US dairy production A ransomware attack targeting Coca-Cola's Fairlife subsidiary has forced a temporary suspension of dairy production across the United States, illustrating the severe real-world operational impacts of cyberattacks on critical manufacturing and OT environments. |
|
■ CVEs IDENTIFIED [CVE-TBD] n8n Enterprise — Authentication bypass via JWT validation flaw (ignores 'iss' claim) |
[CVE-TBD] Splunk — Privilege escalation and credential access |
[CVE-TBD] Zoom — Account takeover and privilege escalation |
[CVE-TBD] F5 NGINX / BIG-IP — Remote code execution, memory leak, and configuration modification |
|
■ THREAT ACTORS Scattered Spider | Cybercrime Group |
Two members (Owen Flowers and Thalha Jubair) sentenced to 5.5 years in the UK for the 2024 Transport for London hack. |
Targeting Ukrainian users with fake CAPTCHA prompts that trick victims into executing malicious PowerShell commands. |
China-linked Threat Actor | State-Sponsored |
Deployed the Daxin kernel-mode backdoor ("srt64.sys") and the new Stupig backdoor within a Taiwan manufacturing firm. |
|
|
|
■ ATT&CK TTPs | T1566.002 | | Phishing: Spearphishing Link | ClickFix lures used to deliver ACR Stealer and TELEPUZ malware. |
| T1204.002 | | User Execution: Malicious File | Sandworm's fake CAPTCHA trick requiring users to copy/paste PowerShell commands. |
| T1059.001 | | Command and Scripting Interpreter: PowerShell | Sandworm executing malicious PowerShell commands. |
| T1489 | | Service Stop | ClickLock terminating macOS visible processes every 210ms to force password entry. |
| T1056.002 | | Input Capture: GUI Input Capture | ClickLock displaying fake system password prompt. |
| T1014 | | Rootkit | Daxin kernel-mode driver backdoor (srt64.sys) used for stealth persistence. |
|
■ PATCH PRIORITY CRITICAL | n8n Enterprise — JWT authentication bypass allowing unauthorized logins — [THN] |
CRITICAL | Splunk — Privilege escalation and credential access vulnerabilities — [SW] |
CRITICAL | Zoom — Account takeover and privilege escalation vulnerabilities — [SW] |
CRITICAL | F5 NGINX & BIG-IP — Remote code execution and memory leak bugs — [SW] |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch n8n Enterprise instances immediately to resolve the JWT token exchange authentication bypass vulnerability [CVE-TBD]. |
| 2 | [P1] Apply critical security updates for Splunk and Zoom to prevent privilege escalation and account takeover [CVE-TBD]. |
| 3 | [P1] Apply security updates for F5 NGINX and BIG-IP to mitigate remote code execution and memory leak vulnerabilities [CVE-TBD]. |
| 4 | [P2] Deploy detection rules for macOS to identify rapid process termination loops and unauthorized Terminal executions associated with ClickLock Stealer. |
| 5 | [P2] Restrict permissions and implement strict tool-binding controls for the Anthropic Claude Chrome Extension to prevent unauthorized click-simulation attacks [CVE-TBD]. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |