Microsoft warns of ClickFix campaign exploiting Windows Terminal to deliver Lumma Stealer
ID: 1c74698f-b05a-59c2-8361-7976ae9fd9af
STIX ID: report--1c74698f-b05a-59c2-8361-7976ae9fd9af
Feed Name: Security Affairs
Threat Score
Microsoft and SecurityAffairs report a ClickFix campaign (February 2026) that tricks users into launching Windows Terminal and pasting hex-encoded, XOR-compressed PowerShell commands from fake CAPTCHAs or prompts; the decoded script downloads and runs multi-stage payloads culminating in a Lumma Stealer component that injects into browser processes, harvests stored credentials, establishes persistence, and exfiltrates data to attacker infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
