On Thursday, Microsoft revealed information on a new, broad ClickFix social engineering effort that uses the Windows Terminal software to launch the Lumma Stealer malware and initiate a complex assault chain.
Instead of telling users to open the Windows Run dialog and type a command into it, the behavior, which was noticed in February 2026, uses the terminal emulator software.
The Microsoft Threat Intelligence team stated in a series of posts on X that this campaign instructs targets to use the Windows + X → I shortcut to launch Windows Terminal (wt.exe) directly, guiding users into a privileged command execution environment that blends into legitimate administrative workflows and appears more trustworthy to users.
The most recent version is noteworthy because it avoids detections meant to flag Run dialog abuse, in addition to using Windows Terminal’s validity to deceive gullible users read more about Microsoft Reveals ClickFix Campaign Using Windows Terminal to Deploy Lumma Stealer.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
