Microsoft warns ClickFix attack targeting Windows Terminal to trick users into running malware


  • Microsoft warns of a ClickFix campaign in development
  • Attackers now abuse Windows Terminal instead of Run
  • Victims tricked into installing Lumma Stealer malware

ClickFix attacks continue to evolve, with a particular new strain of malware ditching the Windows Run program entirely, experts have warned.

Microsoft’s Threat Intelligence team said it saw a “widespread” social engineering campaign starting in February 2026, where the general premise is the same – victims end up on compromised or otherwise malicious websites, where they are presented with a fake security alert asking them to fix a random problem they apparently have.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top