logo

Microsoft Reveals ClickFix Campaign Using Windows Terminal to Deploy Lumma Stealer

ID: 0e5f77dc-4ca1-54cf-8960-eb01e740b407

STIX ID: report--0e5f77dc-4ca1-54cf-8960-eb01e740b407

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-03-06

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Microsoft disclosed a widespread ClickFix social‑engineering campaign that instructs targets to open Windows Terminal and paste a hex‑encoded, XOR‑compressed command which decodes and executes a multi‑stage payload chain culminating in deployment of Lumma Stealer. The chain uses a renamed 7‑Zip to extract payloads, establishes persistence via scheduled tasks, alters Defender exclusions, abuses LOLBins (MSBuild), and employs QueueUserAPC() process injection into browser processes to harvest and exfiltrate stored credentials and browser artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.