Cybersecuritynews
Cyberattackers Exploit ClickFix Script via DNS TXT Records for PowerShell Execution
First seen 5 Feb 2026, 11:54 UTC
•



+4
•85% similarity
•39.9
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Cyberattackers have been exploiting DNS TXT records within the ClickFix script to execute malicious PowerShell commands. This tactic has been linked to the KongTuke campaign, which has been active since mid-2025 and employs social engineering to trick users into addressing fake website errors. Organizations using vulnerable systems are at risk of being compromised through this method.
ThreatCluster AI
How this analysis works