Attackers Using DNS TXT Records in ClickFix Script to Execute Powershell Commands
ID: 730611c4-57f9-5e54-b905-149c5b8a1c35
STIX ID: report--730611c4-57f9-5e54-b905-149c5b8a1c35
Feed Name: cybersecurityNews.com
Threat Score
The report describes the KongTuke campaign (active since mid-2025) that uses a "ClickFix" social-engineering lure to get users to run malicious scripts and now stages next-stage payloads via DNS TXT records to perform fileless PowerShell execution and deploy the Interlock RAT; defenders are advised to monitor DNS anomalies, block suspicious/new domains, and audit PowerShell execution logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
