logo

Microsoft Discloses DNS-Based ClickFix Attack Using Nslookup for Malware Staging

ID: 4a0b9da9-93b2-5423-9621-21408ef00adc

STIX ID: report--4a0b9da9-93b2-5423-9621-21408ef00adc

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-02-15

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Microsoft and multiple security vendors have documented an evolution of ClickFix social‑engineering attacks that now use DNS (nslookup) as a lightweight staging channel to retrieve and execute second‑stage payloads. These chains lead to the download and execution of malware families including ModeloRAT and several infostealers (Lumma, Odyssey, MacSync), delivered via loaders such as CastleLoader and RenEngine and leveraging fake CAPTCHAs, malvertising, compromised/ad‑served pages, and phishing lures across Windows and macOS; campaigns employ persistence (LNK in Startup, LaunchDaemons), evasive checks, and aged/compromised domains for C2, resulting in credential and cryptocurrency theft at international scale.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.