Select a theme from the list.
Insights

From our experts

Latest
Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination HubFileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemoryMicrosoft Brings Agentic Vulnerability Hunting Into Azure GovernmentMicrosoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesPublic Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinyPEEP Turns Trusted Browsers Into Persistent Command CentersBigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingMass Exploitation Hits WordPress Sites Through Two Critical Upload FlawsCitrix NetScaler Authentication Bypass Draws Real-World Attack TrafficProject Zenith Recasts the Windows PC as a Local AI Development PlatformPostGREShell Turns Trusted Replication Accounts Into Server BackdoorsStyleSmuggler Zero-Day Puts Magento Stores on Emergency FootingRogue AI Agents Turn an Abandoned Wiki Into a Secret Coordination Hub
Security Insight

TerminalFix Turns Fake CAPTCHA Checks Into Corporate Network Tunnels

TerminalFix Turns Fake CAPTCHA Checks Into Corporate Network Tunnels
Photo by Brett Sayles on Pexels

Microsoft has identified a ClickFix variant that persuades users to run malicious PowerShell commands through Windows Terminal. Known as TerminalFix, the campaign installs a multistage payload that performs reconnaissance and converts the compromised computer into an encrypted gateway for reaching internal systems.

News Date: 2026-08-31

A deceptive browser verification can now give attackers something more valuable than control of one computer. Microsoft has uncovered a ClickFix variant called TerminalFix that uses fake Cloudflare CAPTCHA prompts to convince victims to execute malicious commands in Windows Terminal or PowerShell.

From Social Engineering to Network Access

The attack begins when a compromised website presents what appears to be a routine human-verification request. Instead of completing a legitimate CAPTCHA, the visitor is instructed to paste and run a command that has already been copied to the clipboard. This action starts a multistage infection process.

The initial command downloads an archive containing a legitimate signed executable and a malicious DLL. The attackers then use steganography to conceal additional components inside image files. These components are extracted and assembled on the victim's system before persistence is established through a scheduled task and a Registry Run key.

TerminalFix subsequently searches for valuable internal assets, including domain controllers, databases, backup servers, mail systems and network gateways. It also collects system details and enumerates Active Directory.

The Reverse Tunnel Changes the Risk

The most concerning component is a custom Python module that creates an encrypted WebSocket connection to attacker infrastructure. This reverse tunnel supports arbitrary TCP proxying, allowing the compromised endpoint to act as a bridge into systems that are not directly exposed to the internet.

In my view, this is what separates TerminalFix from many ordinary information-stealing campaigns. The victim is not merely installing malware. The victim is unintentionally placing an attacker-controlled access point inside the corporate perimeter.

Defensive Priorities

  • Restrict and log PowerShell and Windows Terminal activity where practical.
  • Alert when script interpreters launch from browsers or unusual parent processes.
  • Monitor outbound encrypted WebSocket connections to unfamiliar infrastructure.
  • Investigate unexpected scheduled tasks, Registry persistence and Python components.
  • Train employees never to paste commands supplied by websites.

Organizations that confirm an infection should examine the wider environment for lateral movement and rotate credentials accessible from the affected endpoint. I believe security awareness programs must now treat requests to copy and execute commands as seriously as suspicious attachments. A polished CAPTCHA page should never be allowed to turn a user into the malware installer.

Talk to our team →

Latest

Fileless PHP Rootkit Hides a Web Shell Inside BIG-IP Server MemorySep 9, 2026Microsoft Brings Agentic Vulnerability Hunting Into Azure GovernmentSep 9, 2026Microsoft's Record Patch Tuesday Forces Defenders to Rethink Update PrioritiesSep 9, 2026Public Zero-Day Exploits Put Endpoint Security Tools Under Defensive ScrutinySep 8, 2026PEEP Turns Trusted Browsers Into Persistent Command CentersSep 8, 2026BigBear Shows Why Microsoft 365 MFA Alone Cannot Stop Session HijackingSep 8, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Global CMS Exploitation Wave Plants Webshells on Business Websites4Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication5Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards6Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path