Microsoft Reveals ClickFix Campaign Using Windows Terminal to Deploy Lumma Stealer
ID: 0e5f77dc-4ca1-54cf-8960-eb01e740b407
STIX ID: report--0e5f77dc-4ca1-54cf-8960-eb01e740b407
Feed Name: The Hacker News
Microsoft disclosed a widespread ClickFix social‑engineering campaign that instructs targets to open Windows Terminal and paste a hex‑encoded, XOR‑compressed command which decodes and executes a multi‑stage payload chain culminating in deployment of Lumma Stealer. The chain uses a renamed 7‑Zip to extract payloads, establishes persistence via scheduled tasks, alters Defender exclusions, abuses LOLBins (MSBuild), and employs QueueUserAPC() process injection into browser processes to harvest and exfiltrate stored credentials and browser artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
