Microsoft warns ClickFix attacks targeting Windows Terminal to trick users into running malware
Date:
Mon, 09 Mar 2026 12:35:00 +0000
Description:
Windows Run is no longer the primary vessel for these attacks as hackers find viable alternatives.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Tech Radar Get the TechRadar Newsletter Sign up for
breaking news, reviews, opinion, top tech deals, and more. Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over. You are
now subscribed Your newsletter sign-up was successful An account already exists for this email address, please log in. Subscribe to our newsletter Microsoft warns of evolving ClickFix campaign Attackers now abuse Windows Terminal instead of Run Victims tricked into installing Lumma Stealer malware ClickFix attacks keep evolving, with one particular new malware strain ditching the Windows Run program altogether, experts have warned.
Microsoft 's Threat Intelligence team said it saw a widespread social engineering campaign starting in February 2026 where the general premise is the same - victims end up on compromised, or otherwise malicious websites, where theyre shown a fake security warning asking them to fix a random
problem they apparently have. In classic ClickFix campaigns, that problem is solved by bringing up the Windows Run program (Win + R) and pasting a command that results in the installation of malware. But security solutions have gotten better at spotting malware installations coming from the Windows Run environment, which is why crooks have now replaced it with the Windows Terminal. You may like These fake Chrome extensions will crash your browser
so that hackers can sneak in - here's how to stay safe Microsoft warns infostealer malware is 'rapidly expanding beyond traditional Windows-focused campaigns' and targeting Mac devices Hackers use 'Blue Screen of Death' malware to target victims The evolution of ClickFix Terminal is a modern command-line Windows application that lets users run different command-line tools in one window using tabs, much like a web browser .
It can be brought up with a shortcut, similar to how the Run program is accessed in these attacks, by using the combination Win + X I. Depending on the command being given to the victims, pasting it can trigger one of two observed attack chains. The end result, however, is the same - the installation of the Lumma Stealer.
This is a popular malware variant usually sold as a service on cybercrime forums. It is designed to exfiltrate sensitive data from target Windows computers, such as browser credentials, session cookies, cryptocurrency
wallet information, and other secrets the victim might have stored.
ClickFix is one of the oldest-running malware scams around, dating back to
the earliest days of the internet. It starts with a popup, informing the victim about a problem they have on their computer, and offering a solution
in the same message. Are you a pro? Subscribe to our newsletter Sign up to
the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners
or sponsors By submitting your information you agree to the Terms &
Conditions and Privacy Policy and are aged 16 or over.
Decades ago, that problem was a fake virus infection but today, its mostly about fake CAPTCHAs or locked documents. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!
And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/microsoft-warns-clickfix-attacks-target ing-windows-terminal-to-trick-users-into-running-malware
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)