Sophos researchers have traced a series of Windows intrusions to TerminalFix, an evolving social-engineering technique that persuades users to execute malicious commands in Windows Terminal. Unlike traditional ClickFix attacks that commonly direct victims to the Run dialog, the new variation presents terminal commands as a supposed solution to a browser, document or verification problem.
From User Action to Hidden Tunnel
Once the victim follows the instructions, a PowerShell command downloads an archive containing a legitimate Windows executable, a malicious DLL and a batch script. The script establishes persistence and starts the trusted executable, which loads the hostile DLL through DLL sideloading.
The malicious library launches Lorem Ipsum Loader. Sophos says the loader stores shellcode as ordinary English words rather than obvious binary data, potentially making simple entropy-based detection less effective. A separate lookup table converts the words back into executable bytes.
The malware retrieves command infrastructure from an attacker-controlled profile hosted on a legitimate online platform. Communications are then disguised as JPEG image transfers, although the apparent images contain encoded instructions and data.
A portable Python environment is subsequently installed in a public Windows directory. This environment runs a custom implant that creates an encrypted WebSocket tunnel to attacker-controlled servers. The compromised computer can consequently relay traffic and provide access to internal resources without relying on a conspicuous remote-access application.
Breaking the Infection Chain
- Train employees never to paste commands into PowerShell or Windows Terminal following instructions from a website.
- Monitor terminal and PowerShell processes launched by browsers or recently downloaded files.
- Detect unexpected portable Python installations in shared or public directories.
- Inspect unusual DLL loads involving trusted Windows executables.
- Investigate persistent outbound WebSocket connections to unfamiliar infrastructure.
Sophos associates the broader campaign, tracked as STAC4924, with activity observed since at least March 2026. Earlier operations used poisoned search results and altered Microsoft Teams installers before shifting toward TerminalFix lures.
Expert View
In my view, TerminalFix succeeds because it makes the victim perform the execution step that traditional security controls are designed to block. The command appears intentional because the user pasted it, but the user has no meaningful understanding of what it does.
Defenders should treat instructions to open a terminal as a recognizable phishing indicator. Application control, behavioral monitoring and restrictions on script execution can reduce the impact, but clear employee guidance remains essential because the attack deliberately turns a troubleshooting habit into an initial-access mechanism.
