Threat actors are abusing DNS queries in a new ClickFix social engineering campaign to deliver malware, which makes it the first known use of DNS as a payload delivery channel in these attacks. ClickFix campaigns typically trick users into manually running malicious commands under the pretense of fixing errors, installing updates, or enabling features. In this new variant, attackers use a novel technique where a malicious DNS server delivers the second-stage payload through DNS lookups. Microsoft observed victims being instructed to run an nslookup command that queries an attacker-controlled DNS server instead of the default system resolver. The DNS response […]
The post ClickFix uses DNS to deliver PowerShell malware first appeared on Cybersafe News.
SOCIAL SHARE CARD GENERATOR