ClickFix Attack Uses Windows Terminal to Evade Detection

2026-03-09T13:24:09Z4242ef1bbe3e80f7d4fab75d20c06c0989ad8980b8dcce82e4db39c84ae8758b
.arpaaiciscoclickfixcloned-sitescloudflaredata-breachdns-abuseexploitationgithubincident-responseinstallfixmalwarephishingpolicysd-wansocial-engineeringstealerus-cyber-strategywindows-terminal

What happened

Multiple active threats and significant developments: widespread exploitation attempts observed for Cisco Catalyst SD‑WAN vulnerability CVE-2026-20127; multiple phishing/social‑engineering campaigns ("ClickFix" and "InstallFix") coerce victims into pasting malicious commands into Windows Terminal or replacing legitimate install commands on cloned AI tool sites to deliver malware; abuse of the .arpa TLD and Cloudflare DNS controls to hide malicious hosting; over 100 GitHub repositories distributing the BoryptGrab stealer targeting browsers, crypto wallets and user files; and an ongoing FBI-reve

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
4242ef1bbe3e80f7d4fab75d20c06c0989ad8980b8dcce82e4db39c84ae8758b
Enrichment time
2026-03-09T13:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ClickFix Attack Uses Windows Terminal to Evade Detection · Baitaphish