TerminalFix lurks behind fake CAPTCHAs to deliver a stealth reverse-tunnel backdoor

1 min read
Source: BleepingComputer
TerminalFix lurks behind fake CAPTCHAs to deliver a stealth reverse-tunnel backdoor
Photo: BleepingComputer
TL;DR Summary

Microsoft warns of TerminalFix, a new ClickFix variant that uses fake Cloudflare CAPTCHA prompts to coax victims into running PowerShell in Windows Terminal, then downloads a signed executable and a malicious DLL, with payloads hidden in PNG images via steganography. The malware establishes persistence, conducts AD/network reconnaissance, and employs a custom Python reverse-tunnel over an encrypted WebSocket to reach internal hosts, enabling attacker control and potential lateral movement, data theft, or ransomware. Defenses include restricting/logging PowerShell, monitoring for LockScreenContentServer.exe, hardening browsers/endpoint protections, and rotating credentials if compromise is confirmed.

Share this article

Reading Insights

Total Reads

1

Unique Readers

7

Time Saved

3 min

vs 4 min read

Condensed

87%

70589 words

Want the full story? Read the original article

Read on BleepingComputer