Microsoft warns of TerminalFix attacks deploying reverse tunnels

Microsoft warns of TerminalFix attacks deploying reverse tunnels
TerminalFix is a new ClickFix variant that uses fake Cloudflare CAPTCHA prompts on compromised sites to trick victims into running malicious PowerShell commands in Windows Terminal. Microsoft says the multi-stage attack can establish a reverse tunnel into internal networks, enabling recon, persistence, and potential follow-on actions like credential theft or ransomware deployment. #TerminalFix #Cloudflare #WindowsTerminal #PowerShell

Keypoints

  • TerminalFix uses fake Cloudflare CAPTCHA prompts to lure victims into executing malicious PowerShell commands.
  • The attack differs from typical ClickFix campaigns by targeting Windows Terminal for more complex multi-line scripts.
  • The infection chain downloads a ZIP file with a signed executable and a malicious DLL that launches payloads in memory.
  • Steganographic PNG images are used to hide and rebuild executables and DLL fragments from a C2 server.
  • The malware creates persistence and a Python reverse tunnel that can pivot into internal systems.

Read More: https://www.bleepingcomputer.com/news/security/microsoft-warns-of-terminalfix-attacks-deploying-reverse-tunnels/