TerminalFix Deploys Backdoors via Fake Cloudflare CAPTCHAs
Microsoft reveals TerminalFix, a new ClickFix variant that uses fake Cloudflare CAPTCHAs to trick users into executing malicious PowerShell commands. The campaign targets Windows Terminal and PowerShell to establish reverse-tunnel backdoors.
TL;DR
- TerminalFix is a new ClickFix variant targeting Windows Terminal and PowerShell
- Attackers use fake Cloudflare CAPTCHAs to deceive users into running malicious commands
- The goal is to deploy reverse-tunnel backdoors for persistent access
- Traditional ClickFix campaigns used Windows Run dialog, but TerminalFix increases sophistication
- Organizations should train users to verify CAPTCHA sources and avoid unsolicited terminal commands
Cybersecurity researchers at Microsoft have uncovered a sophisticated new attack campaign called TerminalFix, a variant of the previously known ClickFix malware family. Unlike traditional approaches that target the Windows Run dialog, TerminalFix specifically tricks users into executing malicious commands through Windows Terminal or PowerShell interfaces.
The attackers employ deceptive tactics by presenting victims with what appears to be legitimate Cloudflare CAPTCHA challenges. Once users interact with these fake security prompts, they unknowingly execute commands that establish reverse-tunnel backdoors, providing attackers with persistent access to compromised systems.
Attack Vector and Deception Tactics
- TerminalFix uses convincing fake Cloudflare CAPTCHA interfaces to gain user trust
- Victims are prompted to run seemingly benign commands in Windows Terminal or PowerShell
- The social engineering approach leverages familiarity with legitimate security services
- Attack bypasses traditional Run dialog detection mechanisms by targeting terminal applications
Technical Impact and Defense Recommendations
- Successful execution establishes reverse-tunnel backdoors for persistent system access
- Organizations should implement strict PowerShell execution policies and logging
- User training programs should emphasize verification of security prompts and CAPTCHA sources
- Security teams should monitor for unusual terminal activity and unauthorized outbound connections
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.