New ClickFix attack abuses nslookup to retrieve PowerShell payload via DNS
ID: 26f699e2-142d-5a2e-8724-84b7201c9847
STIX ID: report--26f699e2-142d-5a2e-8724-84b7201c9847
Feed Name: Bleeping Computer
Threat Score
**ClickFix campaign abusing DNS for payload delivery:** Microsoft observed ClickFix social-engineering attacks that instruct victims to run an nslookup query against an attacker-controlled DNS server which returns a PowerShell payload in the DNS response; that payload downloads a ZIP containing a Python runtime and scripts, establishes persistence (VBScript and Startup shortcut), and deploys ModeloRAT to enable remote control of infected systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
