New ClickFix Attack leverages Windows Terminal for Payload Execution
ID: 0f3eb557-e3c8-5b18-852b-2659dd0fff34
STIX ID: report--0f3eb557-e3c8-5b18-852b-2659dd0fff34
Feed Name: cybersecurityNews.com
Security researchers have identified a widespread ClickFix campaign that social-engineers Windows users into opening Windows Terminal (wt.exe) and pasting a clipboarded, obfuscated PowerShell command; the chain decodes in memory, downloads a payload bundle, installs Lumma Stealer to C:\ProgramData\app_config\ctjb, establishes persistence via a scheduled task, and uses QueueUserAPC injection into browser processes (chrome.exe, msedge.exe) to harvest and exfiltrate saved credentials. The campaign leverages Windows Terminal to evade Run-dialog-focused detections and relies on user action rather than a software vulnerability; recommended mitigations are user training, Group Policy restrictions on Terminal/PowerShell, registry and Task Scheduler inspections, and EDR/antimalware configuration to alert on PowerShell spawned by wt.exe.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
