Threat Intelligence

Microsoft warns of DNS-based ClickFix variant

The Hacker News reports that Microsoft has detailed a new evolution of the ClickFix social engineering technique that leverages DNS queries to stealthily deliver malware payloads, signaling a broader escalation in user-driven attack chains.

According to Microsoft, attackers now trick users into running an "nslookup" command via the Windows Run dialog, triggering a DNS request to an external server that returns a second-stage payload. The company said this DNS-based staging reduces reliance on web traffic and blends malicious activity into routine network operations. The campaign ultimately deploys ModeloRAT and establishes persistence through startup shortcuts.

Separately, Bitdefender reported a spike in Lumma Stealer infections distributed through ClickFix-style lures and loaders such as CastleLoader and RenEngine. Researchers noted growing collaboration among malware operators and increased abuse of AI platforms and trusted domains to spread stealers across Windows and macOS systems. Experts warn that ClickFix's success stems from exploiting "procedural trust," urging organizations to strengthen monitoring and user awareness as threat actors refine delivery tactics.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds