Microsoft spots ClickFix campaign getting users to self-pwn on Windows Terminal
ID: ffa1bafa-9644-5c21-80b4-6c2a9e6ee874
STIX ID: report--ffa1bafa-9644-5c21-80b4-6c2a9e6ee874
Feed Name: The Register (Security)
Microsoft Threat Intelligence observed a ClickFix campaign that instructs victims to open Windows Terminal (Win+X → I) and paste encoded PowerShell commands; the commands download a renamed 7‑Zip utility to extract payloads that establish persistence, alter Microsoft Defender exclusions, collect system and browser data, and ultimately deploy the Lumma stealer to harvest browser-stored credentials. An alternate infection chain fetches a batch script that drops and runs a VBScript via MSBuild and uses a cryptocurrency 'EtherHiding' technique before executing the credential-theft routine. Attackers are adapting the ClickFix playbook to use Windows Terminal to evade detections tied to the Run dialog.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
