Select a theme from the list.
Insights

From our experts

Latest
TerminalFix Lures Turn Victims Into Gateways for Covert Network AccessCritical Dell Storage Flaws Put Kubernetes Clusters and Backend Arrays at RiskDTU Identity System Breach Puts Two Decades of Personal Data at RiskPhishing Campaign Turns Legitimate RMM Software Into a Double BackdoorAndroid 17 Closes a Favorite Doorway for Banking MalwareFrontline Education Breach Exposes Sensitive School Employee RecordsSophos Pitches Continuous Security Governance to Organizations Without CISOsPentagon Personnel Breach Exposes Data on More Than Three Million PeopleMicrosoft Warns That AI Is Compressing Cyberattacks From Days to SecondsOpenSSL DTLS Bug Can Spill Heap Data Outside the Encrypted ChannelAI-Speed Intruder Chains Zammad Zero-Days Into Root AccessCrafted Emails Turn Zimbra Servers Into Command-Execution GatewaysTerminalFix Lures Turn Victims Into Gateways for Covert Network AccessCritical Dell Storage Flaws Put Kubernetes Clusters and Backend Arrays at RiskDTU Identity System Breach Puts Two Decades of Personal Data at RiskPhishing Campaign Turns Legitimate RMM Software Into a Double BackdoorAndroid 17 Closes a Favorite Doorway for Banking MalwareFrontline Education Breach Exposes Sensitive School Employee RecordsSophos Pitches Continuous Security Governance to Organizations Without CISOsPentagon Personnel Breach Exposes Data on More Than Three Million PeopleMicrosoft Warns That AI Is Compressing Cyberattacks From Days to SecondsOpenSSL DTLS Bug Can Spill Heap Data Outside the Encrypted ChannelAI-Speed Intruder Chains Zammad Zero-Days Into Root AccessCrafted Emails Turn Zimbra Servers Into Command-Execution Gateways
Security Insight

TerminalFix Lures Turn Victims Into Gateways for Covert Network Access

TerminalFix Lures Turn Victims Into Gateways for Covert Network Access
Photo by Field Engineer on Pexels

Sophos has documented a campaign that replaces familiar ClickFix instructions with prompts telling victims to paste commands into Windows Terminal. The resulting infection deploys Lorem Ipsum Loader, establishes persistence and creates an encrypted tunnel through the compromised computer. The technique allows attackers to reach internal network resources while disguising command traffic as ordinary web activity.

Sophos researchers have traced a series of Windows intrusions to TerminalFix, an evolving social-engineering technique that persuades users to execute malicious commands in Windows Terminal. Unlike traditional ClickFix attacks that commonly direct victims to the Run dialog, the new variation presents terminal commands as a supposed solution to a browser, document or verification problem.

From User Action to Hidden Tunnel

Once the victim follows the instructions, a PowerShell command downloads an archive containing a legitimate Windows executable, a malicious DLL and a batch script. The script establishes persistence and starts the trusted executable, which loads the hostile DLL through DLL sideloading.

The malicious library launches Lorem Ipsum Loader. Sophos says the loader stores shellcode as ordinary English words rather than obvious binary data, potentially making simple entropy-based detection less effective. A separate lookup table converts the words back into executable bytes.

The malware retrieves command infrastructure from an attacker-controlled profile hosted on a legitimate online platform. Communications are then disguised as JPEG image transfers, although the apparent images contain encoded instructions and data.

A portable Python environment is subsequently installed in a public Windows directory. This environment runs a custom implant that creates an encrypted WebSocket tunnel to attacker-controlled servers. The compromised computer can consequently relay traffic and provide access to internal resources without relying on a conspicuous remote-access application.

Breaking the Infection Chain

  • Train employees never to paste commands into PowerShell or Windows Terminal following instructions from a website.
  • Monitor terminal and PowerShell processes launched by browsers or recently downloaded files.
  • Detect unexpected portable Python installations in shared or public directories.
  • Inspect unusual DLL loads involving trusted Windows executables.
  • Investigate persistent outbound WebSocket connections to unfamiliar infrastructure.

Sophos associates the broader campaign, tracked as STAC4924, with activity observed since at least March 2026. Earlier operations used poisoned search results and altered Microsoft Teams installers before shifting toward TerminalFix lures.

Expert View

In my view, TerminalFix succeeds because it makes the victim perform the execution step that traditional security controls are designed to block. The command appears intentional because the user pasted it, but the user has no meaningful understanding of what it does.

Defenders should treat instructions to open a terminal as a recognizable phishing indicator. Application control, behavioral monitoring and restrictions on script execution can reduce the impact, but clear employee guidance remains essential because the attack deliberately turns a troubleshooting habit into an initial-access mechanism.

Talk to our team →

Latest

TerminalFix Lures Turn Victims Into Gateways for Covert Network AccessOct 4, 2026Critical Dell Storage Flaws Put Kubernetes Clusters and Backend Arrays at RiskOct 4, 2026DTU Identity System Breach Puts Two Decades of Personal Data at RiskOct 4, 2026Phishing Campaign Turns Legitimate RMM Software Into a Double BackdoorOct 3, 2026Android 17 Closes a Favorite Doorway for Banking MalwareOct 3, 2026Frontline Education Breach Exposes Sensitive School Employee RecordsOct 3, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication4Global CMS Exploitation Wave Plants Webshells on Business Websites5Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path6Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards