Threats & Adversaries · Credential Theft

Attackers Use Terminal Paste Trick to Steal Credentials

Decoded scripts drop a randomized 7‑Zip, extract payloads, create scheduled‑task persistence and Defender exclusions, exfiltrate data and deploy Lumma Stealer to harvest browser credentials.

4 sources · Mar 9

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-03-07

Every edition of this story: Attackers Use Terminal Paste Trick to Steal Credentials

More from today