Advisory
Published 2026-08-28
Verified 2026-09-19

TerminalFix: fake Cloudflare CAPTCHA pushes a reverse-tunnel via Windows Terminal

Microsoft Threat Intelligence (Security blog dated 28 August 2026; JSON-LD published 29 August) describes TerminalFix, a ClickFix variant that uses compromised websites and a fake Cloudflare CAPTCHA overlay to trick users into pasting a PowerShell command in Windows Terminal or PowerShell rather than the Run dialog. The command downloads a ZIP with a legitimate LockScreenContentServer.exe binary and a malicious dui70.dll for DLL sideloading. Later stages pull payloads hidden in PNG images, persist via Registry Run keys and scheduled tasks, run Active Directory reconnaissance, and deploy a Python reverse-tunnel implant that proxies TCP over an encrypted WebSocket. Microsoft says it did not observe the later hands-on-keyboard steps (privilege escalation, defence tampering, ransomware) in the analysed chain, but treats affected hosts as potential network pivot points. Distinct from the older ClickFix/Vidar WordPress campaign already on this desk. Primary: Microsoft. Secondary: The Hacker News 30 August.

Product
Windows Terminal / PowerShell (ClickFix social engineering)
Versions
n/a (user-executed PowerShell on compromised-site visitors)
Exploited in Australia?
unknown
Patch to
Restrict PowerShell and Run for standard users (AppLocker / WDAC / GPO); hunt DLL sideloading and unexpected Terminal use; treat infected hosts as pivot points

Primary: Microsoft Security Blog (28 Aug 2026) ยท Vendor: The Hacker News (30 Aug; secondary)

tech identity network