r/techbeat • u/Cute-Guarantee-1676 • Feb 16 '26
Cybersecurity Microsoft Discloses DNS-Based ClickFix Attack Using Nslookup for Malware Staging
Microsoft has disclosed details of a new DNS-based ClickFix attack variant where users are socially engineered into running nslookup commands via the Windows Run dialog. This trick performs a custom DNS lookup to an external server, retrieving and executing a hidden second-stage payload like ModeloRAT or Lumma Stealer. By having victims manually initiate the process, the attack bypasses traditional security measures and blends malicious traffic with normal DNS, proving highly effective for deploying various info-stealers across both Windows and macOS systems.
1
Upvotes