Microsoft warns ClickFix attacks targeting Windows Terminal to trick users into running malware



  • Microsoft warns about the evolution of the ClickFix campaign
  • Attackers now abuse Windows Terminal instead of Run
  • Victims tricked into installing Lumma Stealer malware

ClickFix attacks continue to evolve, with one new strain of malware in particular abandoning the Windows Run program entirely, experts warned.

Microsoft’s Threat Intelligence team said it saw a “widespread” social engineering campaign starting in February 2026, where the general premise is the same: victims end up on compromised or malicious websites, where they are shown a fake security warning asking them to fix a random issue they apparently have.



Leave a Comment

Your email address will not be published. Required fields are marked *