TerminalFix lurks behind fake CAPTCHAs to deliver a stealth reverse-tunnel backdoor

Microsoft warns of TerminalFix, a new ClickFix variant that uses fake Cloudflare CAPTCHA prompts to coax victims into running PowerShell in Windows Terminal, then downloads a signed executable and a malicious DLL, with payloads hidden in PNG images via steganography. The malware establishes persistence, conducts AD/network reconnaissance, and employs a custom Python reverse-tunnel over an encrypted WebSocket to reach internal hosts, enabling attacker control and potential lateral movement, data theft, or ransomware. Defenses include restricting/logging PowerShell, monitoring for LockScreenContentServer.exe, hardening browsers/endpoint protections, and rotating credentials if compromise is confirmed.
- Microsoft warns of TerminalFix attacks deploying reverse tunnels BleepingComputer
- TerminalFix campaign deploys a reverse tunnel through multistage intrusion Microsoft
- TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor The Hacker News
- 'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks Dark Reading
- Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines The Register
Reading Insights
1
7
3 min
vs 4 min read
87%
705 → 89 words
Want the full story? Read the original article
Read on BleepingComputer