← Back to blog

TerminalFix Deploys Backdoors via Fake Cloudflare CAPTCHAs

Microsoft reveals TerminalFix, a new ClickFix variant that uses fake Cloudflare CAPTCHAs to trick users into executing malicious PowerShell commands. The campaign targets Windows Terminal and PowerShell to establish reverse-tunnel backdoors.

TL;DR

  • TerminalFix is a new ClickFix variant targeting Windows Terminal and PowerShell
  • Attackers use fake Cloudflare CAPTCHAs to deceive users into running malicious commands
  • The goal is to deploy reverse-tunnel backdoors for persistent access
  • Traditional ClickFix campaigns used Windows Run dialog, but TerminalFix increases sophistication
  • Organizations should train users to verify CAPTCHA sources and avoid unsolicited terminal commands

Cybersecurity researchers at Microsoft have uncovered a sophisticated new attack campaign called TerminalFix, a variant of the previously known ClickFix malware family. Unlike traditional approaches that target the Windows Run dialog, TerminalFix specifically tricks users into executing malicious commands through Windows Terminal or PowerShell interfaces.

The attackers employ deceptive tactics by presenting victims with what appears to be legitimate Cloudflare CAPTCHA challenges. Once users interact with these fake security prompts, they unknowingly execute commands that establish reverse-tunnel backdoors, providing attackers with persistent access to compromised systems.

Attack Vector and Deception Tactics

  • TerminalFix uses convincing fake Cloudflare CAPTCHA interfaces to gain user trust
  • Victims are prompted to run seemingly benign commands in Windows Terminal or PowerShell
  • The social engineering approach leverages familiarity with legitimate security services
  • Attack bypasses traditional Run dialog detection mechanisms by targeting terminal applications

Technical Impact and Defense Recommendations

  • Successful execution establishes reverse-tunnel backdoors for persistent system access
  • Organizations should implement strict PowerShell execution policies and logging
  • User training programs should emphasize verification of security prompts and CAPTCHA sources
  • Security teams should monitor for unusual terminal activity and unauthorized outbound connections

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.