HomeSecurityMicrosoft: ClickFix Attack Using DNS and Nslookup

Microsoft: ClickFix Attack Using DNS and Nslookup

Microsoft has revealed details about a new version of the ClickFix social engineering tactic, in which attackers trick unsuspecting users into executing commands that perform a Domain Name System (DNS) lookup to retrieve the next stage of the malicious payload.

See also: ClickFix attack distributes StealC malware to Windows systems

Microsoft

The attack relies on using the “ nslookup ” command (short for nameserver lookup) to perform a custom DNS lookup that is triggered via the Windows Run dialog. ClickFix is ​​an increasingly popular technique that is traditionally distributed via phishing, malvertising or drive-by download schemes, often redirecting targets to fake landing pages hosting fake CAPTCHA verification or instructions to troubleshoot a non-existent problem on their computers by executing a command via either the Windows Run dialog or the macOS Terminal app.

The attack method has become widespread over the past two years, as it relies on victims infecting their own machines with malware, allowing attackers to bypass security measures. The effectiveness of ClickFix has spawned several variants, including FileFix, JackFix, ConsentFix, CrashFix, and GlitchFix.

“In the final DNS staging using ClickFix, the initial command is executed via cmd.exe and performs a DNS lookup on an external hardcoded DNS server, instead of the system’s,” the Microsoft Threat Intelligence team said. “The result is filtered to extract the `Name:` ​​DNS response, which is executed as the second stage of the malicious payload.”

Microsoft noted that this new variant of ClickFix uses DNS as a “lightweight staging or signaling channel,” allowing the attacker to reach infrastructure under their control and create a new layer of validation before executing the second stage of the malicious payload. “Using DNS in this way reduces reliance on traditional web requests and can help blend malicious activity into normal network traffic,” the company added.

See also: New ClickFix attacks infect systems with LummaStealer

Microsoft: ClickFix Attack Using DNS and Nslookup

The downloaded payload then initiates an attack chain that leads to the download of a ZIP file from an external server, from which a malicious Python script is extracted and executed to perform reconnaissance, execute discovery commands, and drop a Visual Basic Script (VBScript) responsible for launching ModeloRAT, a Python-based remote access Trojan previously distributed via CrashFix.

To establish persistence, a Windows shortcut file (LNK) is created that points to VBScript in the Windows Startup folder, so that the malware is automatically launched every time the operating system starts.

The revelation comes as Bitdefender warned of an increase in Lumma Stealer, driven by ClickFix-style fake CAPTCHA campaigns deploying an AutoIt of CastleLoader, a malware loader associated with an attacker codenamed GrayBravo (formerly TAG-150).

CastleLoader incorporates checks to determine the presence of virtualization software and specific security programs before decrypting and launching the memory stealer malware. In addition to ClickFix, websites advertising cracked software and pirated movies serve as bait for CastleLoader-based attack chains, tricking users into downloading malicious installers or executables that pretend to be MP4 media files.

See also: Expansion of ClickFix attacks using fake CAPTCHAs

Microsoft: ClickFix Attack Using DNS and Nslookup

Other CastleLoader campaigns have also leveraged websites promising cracked software downloads as a launching point for distributing a fake NSIS installer that runs obfuscated VBA scripts before executing the AutoIt script that loads the Lumma Stealer. The VBA loader is designed to execute scheduled tasks that are responsible for ensuring persistence.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS