Microsoft Reveals ClickFix Campaign Using Windows Terminal to Deploy Lumma Stealer
On Thursday, Microsoft revealed information on a new, broad ClickFix social engineering effort that uses the Windows Terminal software to launch the Lumma Stealer malware and initiate a complex assault chain.
Instead of telling users to open the Windows Run dialog and type a command into it, the behavior, which was noticed in February 2026, uses the terminal emulator software.
The Microsoft Threat Intelligence team stated in a series of posts on X that this campaign instructs targets to use the Windows + X → I shortcut to launch Windows Terminal (wt.exe) directly, guiding users into a privileged command execution environment that blends into legitimate administrative workflows and appears more trustworthy to users.
The most recent version is noteworthy because it avoids detection...

