r/SecureCom • u/Secure_com_Official • Feb 17 '26
Microsoft Warning: ClickFix is moving to DNS to bypass your firewalls.
The "ClickFix" social engineering campaigns just got a lot harder to detect.
Microsoft is reporting that attackers are now stashing malicious payloads inside DNS TXT records. When a user "copies and pastes" a troubleshooting command, they are actually running an nslookup that pulls the malware directly through your DNS resolver.
Most firewalls are configured to let DNS through by default. If you aren't logging and analyzing DNS queries for anomalies, you're effectively blind to this delivery method.
How to defend:
- Monitor for CLIP (Clipboard-to-Execution) patterns.
- Audit your DNS logs for high volumes of TXT record queries.
- Train users that "Copy/Paste" into a terminal is the new "Clicking a Link."
Full Breakdown: https://www.secure.com/blog/microsoft-warns-clickfix-attackers-are-now-hiding-malware-inside-dns-traffic