DNS Becomes the New Backdoor: ClickFix Attacks Get Creative While Google Groups Harbor Malware
DNS Becomes the New Backdoor: ClickFix Attacks Get Creative While Google Groups Harbor Malware
We’ve seen social engineering attacks get increasingly sophisticated over the years, but the latest evolution of ClickFix campaigns caught my attention this week. Microsoft disclosed that threat actors are now using DNS queries as a delivery mechanism for malware – and honestly, it’s both clever and concerning.
When nslookup Becomes a Weapon
The traditional ClickFix attack has been around for a while. You know the drill: users get tricked into copying and pasting commands that supposedly fix a fake technical issue. What’s new here is how attackers are using the humble nslookup command to pull down PowerShell payloads directly through DNS queries.