logo

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

ID: 3286380c-97b8-5bc7-8e2c-7b8678a62b28

STIX ID: report--3286380c-97b8-5bc7-8e2c-7b8678a62b28

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-08-30

Date Updated: 2026-08-30

Author: [email protected] (The Hacker News)

...
...

Microsoft has disclosed a ClickFix variant named TerminalFix that lures users into running malicious PowerShell/Windows Terminal commands via fake Cloudflare CAPTCHA pages on compromised websites. The command fetches a ZIP containing a legitimate binary and a rogue DLL that performs DLL sideloading; the malware retrieves steganographically hidden payloads from PNGs, establishes persistence (registry run keys and scheduled tasks), conducts Active Directory/domain reconnaissance, and deploys a Python-based reverse-tunnel backdoor (client.py) to tunnel arbitrary TCP traffic to attacker infrastructure (gitnow.dev:443), enabling internal network access and potential lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.