Skip to main content
Back to Newswire
Security

Microsoft details TerminalFix campaign using fake CAPTCHAs and reverse tunnels

Microsoft details TerminalFix campaign using fake CAPTCHAs and reverse tunnels Image: Primary
Microsoft disclosed a ClickFix variant called TerminalFix that directs victims from compromised websites to fake Cloudflare CAPTCHA pages and prompts them to run malicious PowerShell commands. The campaign targets organizations across multiple sectors. Microsoft said the attack uses DLL sideloading, payloads hidden in PNG files, Active Directory reconnaissance and a Python-based reverse-tunnel implant. The implant can tunnel TCP traffic through an encrypted WebSocket channel and let an attacker reach hosts visible from the compromised network. Microsoft recommended restricting PowerShell execution, monitoring DLL sideloading and enabling script-block logging.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire