logo

New ClickFix attack abuses nslookup to retrieve PowerShell payload via DNS

ID: 26f699e2-142d-5a2e-8724-84b7201c9847

STIX ID: report--26f699e2-142d-5a2e-8724-84b7201c9847

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-02-16

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

**ClickFix campaign abusing DNS for payload delivery:** Microsoft observed ClickFix social-engineering attacks that instruct victims to run an nslookup query against an attacker-controlled DNS server which returns a PowerShell payload in the DNS response; that payload downloads a ZIP containing a Python runtime and scripts, establishes persistence (VBScript and Startup shortcut), and deploys ModeloRAT to enable remote control of infected systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.