{"id":2608,"date":"2026-08-30T09:23:45","date_gmt":"2026-08-30T09:23:45","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2608"},"modified":"2026-08-30T09:23:45","modified_gmt":"2026-08-30T09:23:45","slug":"terminalfix-uses-fake-cloudflare-captchas-to-deploy-reverse-tunnel-backdoor","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2608","title":{"rendered":"TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 30, 2026<\/span><\/span><span class=\"p-tags\">Social Engineering \/ Malware<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhpxriybAzLw0daA0mtL3sZd04fy8Sal4s0mrBAz2-ksjwfP2V08YK_KbCJY57hKG28Kt6gn2mKq4HFSpkG2MNvA3Oz6MhNUe77_1Nvpahn2nnCFHPpxIlp5Ix4DvAZw08qXtxt1M-4zCtSENbBkODQyP_WDp9j3PXACc0XKYk1BK1K-2Xabho1cBPqerW9\/s1700-nu-rw-lo-l85-e365\/cf-clickfix.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Microsoft has disclosed details of a new ClickFix variant, dubbed <strong>TerminalFix<\/strong>, that aims to trick users into running a malicious command in Windows Terminal or PowerShell.<\/p>\n<p>\u00abWhile traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex, multi-line scripts execute successfully,\u00bb Microsoft security researchers Sagar Patil, Suriyaraj Natarajan, and Parasharan Raghavan <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/08\/28\/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion\/\" target=\"_blank\">said<\/a> in an analysis published this week.<\/p>\n<p>The campaign, targeting organizations across multiple sectors, leverages compromised websites as a starting point to serve fake Cloudflare CAPTCHA verifications that prompt unsuspecting site visitors to copy and execute a malicious PowerShell command.<\/p>\n<p>The attack chain, per the Windows maker, is a sophisticated multi-stage process that leverages DLL sideloading, steganographic payload extraction, extensive Active Directory reconnaissance, and a bespoke custom reverse-tunnel implant that grants the attacker persistent, network-level proxy access through the infected machine.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/zero-trust-claude-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8iAp2j8rqTq6aptj6yiYHC-B73UxnWI2NQMt0azp6OVLq9JkO8cpYokLWa8t_IKqrHKPsaM5D_lQ9Ip7kZTi3at4oYfzN1m1b_T4b6MuzBWtmlhdLcQ0nZHicD94rliREFDRewsKBQCTYrAAVNzYKj84_0EZskDUxvkc972s9fYAqcQGEQjVZTc0cr7TB\/s728-nu-rw-lo-l85-e365\/ThreatLocker-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Specifically, the PowerShell command is designed to download a ZIP archive containing a legitimate binary (\u00abLockScreenContentServer.exe\u00bb) and a rogue DLL (\u00abdui70.dll\u00bb) in order to initiate a DLL sideloading attack.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The sideloaded DLL is responsible for retrieving next-stage payloads hidden within PNG images from external domains (\u00abbestsocialmedianewspapper[.]com\u00bb or \u00abofflineupdater[.]com\u00bb), establishes persistence via both Registry Run keys and scheduled tasks, carries out domain reconnaissance, and then deploys a Python-based reverse-tunnel command-and-control (C2) implant.<\/p>\n<p>The backdoor (\u00abclient.py\u00bb) is equipped to tunnel arbitrary TCP traffic back to attacker-controlled infrastructure (\u00abgitnow[.]dev:443\u00bb) through an encrypted WebSocket channel, as well as enable the C2 server to reach any host visible from the victim&#8217;s network.<\/p>\n<p>The reconnaissance phase involves the following steps &#8211;<\/p>\n<ul>\n<li>Collect system metadata<\/li>\n<li>Perform domain trust discovery, domain admin enumeration, and Active Directory user and computer searches<\/li>\n<li>Ping named servers to map the internal network topology<\/li>\n<\/ul>\n<p>The attack also delivers a persistent PowerShell file-watch loop that monitors a text file for new commands, executes them via Invoke-Expression, and writes results to an output file.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-nu-rw-lo-l85-e365\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abThis type of intrusion is particularly dangerous because it provides attackers with direct access to an organization&#8217;s internal network through the reverse tunnel,\u00bb Microsoft said. \u00abThe observed reconnaissance and reverse-tunnel capability could enable an attacker to identify and reach additional systems from a compromised host.\u00bb<\/p>\n<p>The tech giant has warned that such access can be abused further to escalate privileges, disarm security controls, exfiltrate sensitive data, and deploy ransomware, making TerminalFix a serious threat to enterprise environments.<\/p>\n<p>To mitigate the threat, it&#8217;s advised to restrict PowerShell and Run dialog execution for standard users through AppLocker, Application Control for Windows, or Group Policy; consider blocking or auditing the Windows Run dialog (\u00abWin+R\u00bb) if it&#8217;s not required; monitor for DLL sideloading indicators; train employees to keep an eye out for ClickFix attacks; and enable PowerShell script block logging to detect and analyze obfuscated or encoded commands.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Aug 30, 2026Social Engineering \/ Malware Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2609,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[179,2616,927,229,150,3239,3238],"class_list":["post-2608","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-backdoor","tag-captchas","tag-cloudflare","tag-deploy","tag-fake","tag-reversetunnel","tag-terminalfix"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2608","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2608"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2608\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2609"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2608"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2608"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2608"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}