HomeSecurityMicrosoft: New ClickFix campaign distributes Lumma Stealer

Microsoft: New ClickFix campaign distributes Lumma Stealer

Microsoft has revealed details of a new, widespread ClickFix campaign that exploits the Windows Terminal application to trigger a sophisticated attack chain and deploy the Lumma Stealer malware . The activity, observed in February 2026 , uses the terminal emulator program instead of directing users to launch the Windows Run dialog box and paste a command into it. 

Microsoft ClickFix Lumma Stealer

This campaign instructs targets to use the Windows + X → I shortcut to directly launch Windows Terminal (wt.exe) , leading users to a privileged command execution environment that is mixed with legitimate administrative processes and appears more trustworthy. This technique is an evolution of the traditional ClickFix methods that appeared in 2024 , which tricked users through fake CAPTCHA pages , advertisements, or browser issues.

See also: Pastebin comments promote ClickFix JavaScript attack

What makes this variant notable is that it bypasses detection mechanisms, having been specifically designed to flag abuse of the Run. At the same time, it exploits the legitimacy of the Windows Terminal to trick users into executing malicious commands delivered via fake CAPTCHA, troubleshooting prompts, or other verification-type baits.

Technical Details of the ClickFix Attack

The attack chain, after the breach, is also unique: when the user pastes a hex-encoded, XOR-compressed command (which they have copied from the ClickFix into a Windows Terminal session), it creates additional Terminal/PowerShell instances to eventually call a PowerShell process, responsible for decoding the script. This leads to the download of a ZIP payload and a legitimate but renamed 7-Zip binary, which is saved to disk with a random filename.

See also: Microsoft: ClickFix Attack Using DNS and Nslookup

Microsoft: New ClickFix campaign distributes Lumma Stealer

The tool then extracts the file ZIP, triggering a multi-stage attack chain that includes retrieving more payloads, creating persistence via scheduled tasks, configuring Microsoft Defender, extracting machine and network data, and deploying Lumma Stealer using a technique called QueueUserAPC().

The stealer targets high-value browser artifacts, including Web Data and Login Data, by collecting stored credentials and exporting them to infrastructure controlled by the attackers.

Microsoft also identified a second attack path, where when the compressed command is pasted into Windows Terminal , it downloads a randomly named batch script to the “ AppData\Local ” folder using “ cmd.exe ” to write a Visual Basic Script to the Temp folder .

See also: ClickFix attack distributes StealC malware to Windows systems

Microsoft: New ClickFix campaign distributes Lumma Stealer

To protect against these attacks, experts recommend enabling Microsoft Defender for Endpoint with network and web protection against malicious websites, enabling PowerShell script block logging for visibility into encrypted commands, and setting execution policies to AllSigned or RemoteSigned.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS