ClickFix added nslookup commands to its arsenal for downloading RATs

ClickFix added nslookup commands to its arsenal for downloading RATs

• ClickFix uses fake CAPTCHAs and bogus updates to trick users into executing malicious commands. • Traditional mshta and PowerShell vectors are blocked, so attackers shifted to ns

Threat Intelligence · February 16, 2026 (updated February 24, 2026) · 1 min · 207 words
New ClickFix attack abuses nslookup to retrieve PowerShell payload via DNS

New ClickFix attack abuses nslookup to retrieve PowerShell payload via DNS

• Threat actors are now abusing DNS queries as part of ClickFix social engineering attacks to deliver malware, making this the first known use of DNS as a channel in these campaign

Cybersecurity · February 16, 2026 (updated February 24, 2026) · 2 min · 276 words
Microsoft Discloses DNS-Based ClickFix Attack Using Nslookup for Malware Staging

Microsoft Discloses DNS-Based ClickFix Attack Using Nslookup for Malware Staging

• Microsoft has disclosed details of a new version of the ClickFix social engineering tactic in which the attackers trick unsuspecting users into running commands that carry out a

Cybersecurity · February 15, 2026 (updated February 24, 2026) · 2 min · 310 words