logo

Microsoft alerts on DNS-based ClickFix variant delivering malware via nslookup

ID: 5802a39a-8550-50ca-9be4-ae2d06adb85d

STIX ID: report--5802a39a-8550-50ca-9be4-ae2d06adb85d

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-02-16

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Microsoft warns of a ClickFix variant that social-engineers victims into executing a malicious nslookup via the Windows Run dialog to retrieve a second-stage payload over DNS, which downloads a ZIP containing a portable Python bundle and malicious scripts and ultimately installs ModeloRAT with persistence via a Startup shortcut. The campaign uses DNS-based staging to reduce reliance on web requests and evade detection while performing reconnaissance and discovery on compromised hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.