Cyberattackers Exploit ClickFix Script via DNS TXT Records for PowerShell Execution

Cyberattackers Exploit ClickFix Script via DNS TXT Records for PowerShell Execution

First seen 5 Feb 2026, 11:54 UTC CybersecuritynewsGbhackersCyberpressBleepingcomputerPhoneworld.Pk+4 85% similarity 39.9

Article Content

Browse articles
ThreatCluster

Cyberattackers have been exploiting DNS TXT records within the ClickFix script to execute malicious PowerShell commands. This tactic has been linked to the KongTuke campaign, which has been active since mid-2025 and employs social engineering to trick users into addressing fake website errors. Organizations using vulnerable systems are at risk of being compromised through this method.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story