Threats · 190 days ago
Decoded scripts drop a randomized 7‑Zip, extract payloads, create scheduled‑task persistence and Defender exclusions, exfiltrate data and deploy Lumma Stealer to harvest browser credentials.
4 sources covering this story
ClickFix Attack Uses Windows Terminal to Evade Detection
Fake CAPTCHA pages instruct victims to paste malicious commands in the Windows Terminal instead of the Run dialog.
ClickFix attackers using new tactic to evade detection, says Microsoft
Unwitting victims are now being tricked into installing malware via Windows Terminal, but some experts say this is old news.
Microsoft Reveals ClickFix Campaign Using Windows Terminal to Deploy Lumma Stealer
Microsoft reveals ClickFix campaign abusing Windows Terminal to deliver Lumma Stealer and steal browser credentials.
Fake Claude Code install guides push infostealers in InstallFix attacks
Threat actors are employing a new variation of the ClickFix social engineering technique called InstallFix to convince users into running malicious commands under the pretext of installing legitimate command line interface (CLI) tools.
Part of the PlainSec briefing for 2026-03-07