Microsoft warns of ClickFix attacks targeting Windows Terminal to trick users into running malware


  • Microsoft warns about the evolution of the ClickFix campaign
  • Attackers now abuse Windows Terminal instead of Run
  • Victims were tricked into installing Lumma Stealer malware

ClickFix attacks continue to evolve, with a particular new malware strain abandoning the Windows Run program altogether, experts have warned.

Microsoft’s Threat Intelligence team said it saw a “widespread” social engineering campaign starting in February 2026, the general principle of which is the same: victims end up on compromised or malicious websites, where they are presented with a fake security warning asking them to fix a random problem they appear to have.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top