TerminalFix: fake Cloudflare CAPTCHA pushes a reverse-tunnel via Windows Terminal
Microsoft Threat Intelligence (Security blog dated 28 August 2026; JSON-LD published 29 August) describes TerminalFix, a ClickFix variant that uses compromised websites and a fake Cloudflare CAPTCHA overlay to trick users into pasting a PowerShell command in Windows Terminal or PowerShell rather than the Run dialog. The command downloads a ZIP with a legitimate LockScreenContentServer.exe binary and a malicious dui70.dll for DLL sideloading. Later stages pull payloads hidden in PNG images, persist via Registry Run keys and scheduled tasks, run Active Directory reconnaissance, and deploy a Python reverse-tunnel implant that proxies TCP over an encrypted WebSocket. Microsoft says it did not observe the later hands-on-keyboard steps (privilege escalation, defence tampering, ransomware) in the analysed chain, but treats affected hosts as potential network pivot points. Distinct from the older ClickFix/Vidar WordPress campaign already on this desk. Primary: Microsoft. Secondary: The Hacker News 30 August.
- Product
- Windows Terminal / PowerShell (ClickFix social engineering)
- Versions
- n/a (user-executed PowerShell on compromised-site visitors)
- Exploited in Australia?
- unknown
- Patch to
- Restrict PowerShell and Run for standard users (AppLocker / WDAC / GPO); hunt DLL sideloading and unexpected Terminal use; treat infected hosts as pivot points
Primary: Microsoft Security Blog (28 Aug 2026) ยท Vendor: The Hacker News (30 Aug; secondary)
