Microsoft alerts on DNS-based ClickFix variant delivering malware via nslookup

3 Min Read

Microsoft warns of a new ClickFix variant that tricks users into running DNS commands to fetch malware via nslookup.

Microsoft has revealed a new ClickFix variant that deceives users into running a malicious nslookup command through the Windows Run dialog to retrieve a second-stage payload via DNS. ClickFix typically uses fake CAPTCHA or error messages to trick victims into infecting their own systems, helping attackers evade security defenses. The technique has evolved into multiple variants over the past two years.

- Advertisement -

“Microsoft Defender researchers observed attackers using yet another evasion approach to the ClickFix technique: Asking targets to run a command that executes a custom DNS lookup and parses the `Name:` response to receive the next-stage payload for execution.” Microsoft wrote on X.

In the latest ClickFix variant, attackers use cmd.exe to perform a DNS lookup against a hard-coded external server. The Name: response is extracted and executed as the second-stage payload. This DNS-based approach lets attackers signal and deliver payloads via their own infrastructure, reducing reliance on web requests and helping the malicious activity blend into normal network traffic.


What do you think? Post a comment.


Microsoft warns that this new ClickFix variant uses DNS as a “lightweight staging or signaling channel,” allowing attackers to reach their own infrastructure and add a validation step before running the second-stage payload. This method reduces reliance on web requests and helps hide malicious activity in normal network traffic. The payload downloads a ZIP from an external server, extracts a Python script to conduct reconnaissance, and drops a VBScript that launches ModeloRAT, a Python-based RAT.

- Advertisement -

EXPLORE MORE

Trump renames Lake Ontario as Lake America amid trade war

After floating the idea on Tuesday, President Donald Trump issued an Executive…

Was Gloria Steinem a CIA agent working to overthrow the family?

Top feminist Gloria Steinem who died this week at age 92 may…

Wanted: Suspects for Attempted Robbery in the 22nd District [VIDEO]

The Philadelphia Police Department-Central Detective Division is seeking the public’s help in…

PATRIOT MISSILE SHORTAGE: FOUR-YEAR DELAY LOOMS FOR DEFENSE GIANT ORDERS

WASHINGTON — Pentagon planners and foreign military attachés face a sobering industrial…

SmartLoader hackers clone Oura MCP project to spread StealC malware

Hackers used a fake Oura MCP server to trick users into downloading…

Attackers achieve persistence by creating a Windows shortcut in the Startup folder, ensuring the malware runs at every system startup.

Microsoft alerts on DNS-based ClickFix variant delivering malware via nslookup | Philly PI

“Upon execution of the second-stage payload provided by the DNS response, the attack proceeds through an attack chain leading to downloading hxxp://azwsappdev[.]com/wdhmgpmihudkueq[.]zip and extracting a portable Python bundle and malicious python code, then running a malicious Python script for host/domain reconnaissance, performing a series of discovery commands, before dropping the final payload `%APPDATA%\WPy64-31401\python\script.vbs` and `%STARTUP%/MonitoringService.lnk`pointing to the VBScript for persistence. This final payload is a remote access trojan and called ModeloRAT.” conlcudes the report.

Pierluigi Paganini



Share This Article

Resurfaced Childhood Photo of Hasan Piker Triggers Online Debate Over Wealth and Authenticity

An old photograph of political commentator and Twitch streamer…

‘SCARED TO DEATH’: 48 HOURS ABOARD AMERICA’S MIGHTIEST SUPERCARRIER

ATLANTIC OCEAN — From the flight deck, the view…

Cops Raid Home of Rep. Ilhan Omar’s Son, Seizing Firearms and Ammunition

MINNEAPOLIS — Police executed a search warrant at a…

Canada Is Poaching America’s Top Scientists

Canada is taking advantage of growing uncertainty within the…

Kurt Weldon’s 9/11 Bombshell on Jimmy Dore

Former Republican Congressman Kurt Weldon—who served Pennsylvania's 7th district…

How June Lapine Dismantled Hasan Piker’s Image and Forced a Wardrobe Transformation

June Lapine, known widely online as Shoe0468 (or Shoe013),…

From Track Star to WWE Champion: Inside Lainey Reid’s Rise to the Top

Whether she’s dominating in the ring on WWE’s SmackDown…

Department of Justice Indicts Southern Poverty Law Center on Federal Fraud Charges

In a major federal enforcement action, Acting Attorney General…

CONVERSATION

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted