ClickFix malware campaigns hide payloads behind DNS lookups, researchers find
Security researchers at Flare identified a ClickFix social-engineering campaign distributing the CrocoRat remote access Trojan and cryptocurrency stealer via a misspelled domain showing a fake house-wiring image. Instead of fetching malware directly, the pasted PowerShell command queries an attacker-controlled DNS TXT record, which returns instructions for the next stage of the attack.
GoKawiil's interpretation of the reporting above, not reported fact.
By routing the payload retrieval through DNS lookups rather than a direct download, attackers make it harder for security tools to flag the initial command as malicious, since the destructive code is not immediately visible when the victim pastes it. This suggests ClickFix operators are actively adapting their techniques to stay ahead of detection systems that have learned to spot earlier versions of the scam.
- ClickFix attacks trick victims into pasting malicious commands into PowerShell, Run, or Terminal.
- A new campaign hides the CrocoRat payload behind a DNS TXT record query instead of a direct link.
- The evolving technique suggests attackers are adjusting tactics specifically to evade security detection.
YubiKey 5C NFC Security Key — Since ClickFix attacks rely on tricking people into manually executing malicious commands, strengthening authentication is a smart complementary defense. A hardware security key like the YubiKey adds phishing-resistant multi-factor authentication, making stolen credentials far less useful to attackers even if a social engineering attempt partially succeeds.
See YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.Source: darkreading.com — Alexander Culafi, 2026-10-06
Published there as: “ClickFix Attacks Evolve to Better Hide Malicious Payloads”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.