TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
AI Summary
Microsoft has uncovered a new variant of the ClickFix campaign dubbed TerminalFix, which uses social engineering to trick users into executing a malicious PowerShell command via fake Cloudflare CAPTCHA pages served through compromised websites. The attack employs DLL sideloading using a legitimate binary and a malicious DLL to execute multi-stage payloads, including steganographic extraction from PNG files and extensive Active Directory reconnaissance. The final payload is a Python-based reverse-tunnel backdoor that establishes persistent C2 access via an encrypted WebSocket, enabling attackers to pivot across internal networks. This campaign poses a serious risk to enterprise environments due to its lateral movement and persistence capabilities.
AI-extracted · verify before operational use