hacker-news · Crawled Sep 1, 2026

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

6 IoCs
Read original article ↗

AI Summary

Microsoft has uncovered a new variant of the ClickFix campaign dubbed TerminalFix, which uses social engineering to trick users into executing a malicious PowerShell command via fake Cloudflare CAPTCHA pages served through compromised websites. The attack employs DLL sideloading using a legitimate binary and a malicious DLL to execute multi-stage payloads, including steganographic extraction from PNG files and extensive Active Directory reconnaissance. The final payload is a Python-based reverse-tunnel backdoor that establishes persistent C2 access via an encrypted WebSocket, enabling attackers to pivot across internal networks. This campaign poses a serious risk to enterprise environments due to its lateral movement and persistence capabilities.

AI-extracted · verify before operational use

Indicators of Compromise 6 extracted

Type Value Detail
Domain bestsocialmedianewspapper[.]com Details →
Domain offlineupdater[.]com Details →
Domain gitnow[.]dev Details →
Filename LockScreenContentServer.exe Details →
Filename dui70.dll Details →
Filename client.py Details →