TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
ID: 3286380c-97b8-5bc7-8e2c-7b8678a62b28
STIX ID: report--3286380c-97b8-5bc7-8e2c-7b8678a62b28
Feed Name: The Hacker News
Microsoft has disclosed a ClickFix variant named TerminalFix that lures users into running malicious PowerShell/Windows Terminal commands via fake Cloudflare CAPTCHA pages on compromised websites. The command fetches a ZIP containing a legitimate binary and a rogue DLL that performs DLL sideloading; the malware retrieves steganographically hidden payloads from PNGs, establishes persistence (registry run keys and scheduled tasks), conducts Active Directory/domain reconnaissance, and deploys a Python-based reverse-tunnel backdoor (client.py) to tunnel arbitrary TCP traffic to attacker infrastructure (gitnow.dev:443), enabling internal network access and potential lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
