TerminalFix is a new ClickFix variant that uses fake Cloudflare CAPTCHA prompts on compromised sites to trick victims into running malicious PowerShell commands in Windows Terminal. Microsoft says the multi-stage attack can establish a reverse tunnel into internal networks, enabling recon, persistence, and potential follow-on actions like credential theft or ransomware deployment. #TerminalFix #Cloudflare #WindowsTerminal #PowerShell
Keypoints
- TerminalFix uses fake Cloudflare CAPTCHA prompts to lure victims into executing malicious PowerShell commands.
- The attack differs from typical ClickFix campaigns by targeting Windows Terminal for more complex multi-line scripts.
- The infection chain downloads a ZIP file with a signed executable and a malicious DLL that launches payloads in memory.
- Steganographic PNG images are used to hide and rebuild executables and DLL fragments from a C2 server.
- The malware creates persistence and a Python reverse tunnel that can pivot into internal systems.