Signal

Microsoft Reveals ClickFix Campaign Using Windows Terminal to Deploy Lumma Stealer

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-03-05 23:53 UTCUpdated 2026-03-06 21:15 UTC
rss
aicso_online
Source links open
Source links and full evidence are open here. Pro adds archive history, compare-over-time, alerts, exports, and workflow. Business adds Feed API integrations and team usage.
No card needed for the free brief.
Evidence trail (top sources)
top sources (4 domains)domains are deduped. counts indicate coverage, not truth.
4 top sources shown
Beware of fake OpenClaw installers, even if Bing points you to GitHub
Malwarebytes Threat Analysis · News · malwarebytes.com · 2026-03-06 11:11 UTC
Overview

Attackers are abusing OpenClaw ’s popularity by seeding fake “installers” on GitHub, boosted by Bing AI search results, to deliver infostealers and proxy malware instead of the AI assistant users were looking for.

Score total
1.38
Momentum 24h
5
Posts
5
Origins
4
Source types
1
Duplicate ratio
0%
All evidence
All evidence
ClickFix attackers using new tactic to evade detection, says Microsoft
CSO Online · csoonline.com · 2026-03-06 21:15 UTC
Microsoft spots ClickFix campaign getting users to self-pwn on Windows Terminal
The Register Security · go.theregister.com · 2026-03-06 13:37 UTC
Beware of fake OpenClaw installers, even if Bing points you to GitHub
Malwarebytes Threat Analysis · malwarebytes.com · 2026-03-06 11:11 UTC
Microsoft Reveals ClickFix Campaign Using Windows Terminal to Deploy Lumma Stealer
thehackernews · thehackernews.com · 2026-03-06 06:44 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 4Origin domains: 4Duplicates: -
Showing 4 / 5
Top publishers (this list)
  • CSO Online (1)
  • The Register Security (1)
  • Malwarebytes Threat Analysis (1)
  • thehackernews (1)
Top origin domains (this list)
  • csoonline.com (1)
  • go.theregister.com (1)
  • malwarebytes.com (1)
  • thehackernews.com (1)