logo

Microsoft warns of ClickFix campaign exploiting Windows Terminal to deliver Lumma Stealer

ID: 1c74698f-b05a-59c2-8361-7976ae9fd9af

STIX ID: report--1c74698f-b05a-59c2-8361-7976ae9fd9af

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-03-06

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Microsoft and SecurityAffairs report a ClickFix campaign (February 2026) that tricks users into launching Windows Terminal and pasting hex-encoded, XOR-compressed PowerShell commands from fake CAPTCHAs or prompts; the decoded script downloads and runs multi-stage payloads culminating in a Lumma Stealer component that injects into browser processes, harvests stored credentials, establishes persistence, and exfiltrates data to attacker infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.