Microsoft Threat Intelligence disclosed a new ClickFix social-engineering variant that abuses DNS lookups as a lightweight staging/signaling channel. Victims are redirected via phishing, malvertising, or compromised sites to fake prompts (e.g., bogus CAPTCHA or “fix this issue” messages) that instruct them to run a command through the Windows Run dialog (or similar execution paths). The initial command launches cmd.exe and runs nslookup against a hard-coded, attacker-controlled external DNS server rather than the system’s default resolver, reducing reliance on traditional web requests and helping activity blend into normal network traffic.
In the observed technique, the attacker-controlled DNS response is parsed and the output is filtered to extract the Name: field, which is repurposed to carry the second-stage payload; that extracted content is then executed on the endpoint. Reporting notes this approach adds a validation step (confirming an active target before delivering heavier components) and can bypass some security controls because the user effectively initiates the infection themselves. The activity is positioned as part of the broader, rapidly evolving ClickFix ecosystem, which has spawned multiple variants (e.g., CrashFix, FileFix, JackFix, ConsentFix, GlitchFix) as adversaries iterate on lures and delivery mechanics.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
After the disclosure, researcher Muhammad Hassoub published CrowdStrike CQL hunting queries and detection guidance focused on suspicious nslookup.exe execution and anomalous DNS patterns tied to the campaign. The recommendations urged defenders to expand monitoring beyond PowerShell-centric detections to catch living-off-the-land DNS abuse.
By mid-February 2026, Microsoft publicly warned that attackers were using DNS as a staging and signaling channel in ClickFix campaigns, helping the activity blend into normal network traffic and dynamically change payloads. The disclosure highlighted abuse of nslookup and the use of the DNS 'Name' field to carry executable content.
Microsoft Defender researchers observed a new ClickFix variant that instructs victims to run an nslookup command against an attacker-controlled DNS server, extracting a second-stage payload from the DNS response. The chain then downloaded a ZIP, ran malicious Python-based reconnaissance components, established persistence with a VBScript and Startup shortcut, and deployed ModeloRAT.
In 2025, law enforcement disrupted Lumma Stealer operations, though later reporting said the malware ecosystem remained resilient and continued to appear in ClickFix-style delivery chains. This event is mentioned as background to concurrent social-engineering campaigns active in 2026.
Over 2024 and 2025, ClickFix expanded beyond early techniques into several variants, including account-takeover and in-browser transaction-hijacking approaches. Reports describe a steady evolution of fake CAPTCHA, error, and troubleshooting lures used to trick users into self-infecting systems.
ClickFix social-engineering activity was first spotted around 2024, according to later reporting that places its initial discovery roughly two years before February 2026. The campaigns relied on fake prompts and user-executed commands rather than software exploitation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcedarkreading.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.