Microsoft Discloses DNS-Based ClickFix Attack Using Nslookup for Malware Staging
Microsoft revealed information about a new iteration of the ClickFix social engineering technique, in which the attackers fool gullible victims into executing commands that perform a DNS lookup in order to obtain the subsequent payload.
The attack specifically uses the "nslookup" command, which stands for "nameserver lookup," to do a custom DNS lookup that is initiated via the Windows Run dialog.
ClickFix is a growingly common technique that is typically distributed through drive-by download schemes, phishing, or malvertising. It frequently directs victims to fraudulent landing pages that display phony CAPTCHA verification or instructions to fix a computer issue that doesn't exist by executing a command via the macOS Terminal application or the Windows Run dialog.
Over the past t...

