TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
Microsoft has detailed TerminalFix, a new ClickFix variant that tricks victims into running malicious commands in Windows Terminal or PowerShell through fake Cloudflare CAPTCHA pages on compromised websites. The attack uses DLL sideloading, steganographic payload extraction, Active Directory reconnaissance, and a custom reverse-tunnel implant to maintain persistent access and move deeper into enterprise networks. #TerminalFix #Microsoft #Cloudflare #LockScreenContentServer.exe #dui70.dll #client.py

Keypoints

  • TerminalFix is a ClickFix variant that targets Windows Terminal and PowerShell.
  • Fake Cloudflare CAPTCHA pages lure users into executing a malicious PowerShell command.
  • The attack uses DLL sideloading and hidden payloads inside PNG images.
  • The implant establishes persistence and provides a reverse tunnel into the victim network.
  • Microsoft recommends PowerShell controls, DLL sideloading monitoring, and user awareness training.

Read More: https://thehackernews.com/2026/08/terminalfix-uses-fake-cloudflare.html