TerminalFix Malware Exploits Fake Cloudflare CAPTCHA to Install Reverse‑Tunnel Backdoor
Microsoft has revealed a new variant of the ClickFix malware family, dubbed TerminalFix, that leverages counterfeit Cloudflare CAPTCHA pages to coax Windows users into executing malicious commands through Windows Terminal or PowerShell.
Unlike earlier ClickFix campaigns, which typically directed victims to the Windows Run dialog, TerminalFix presents a web page that mimics Cloudflare’s security challenge. When the user clicks “Verify,” a script injects a command line that launches the Windows Terminal, runs a PowerShell payload and establishes a reverse‑tunnel connection to a remote server.
The reverse tunnel gives attackers persistent, low‑profile access to the compromised system, allowing them to exfiltrate data, download additional tools, or move laterally within a network. Microsoft’s analysis indicates the payload uses common Windows utilities to avoid detection, and the tunnel traffic is encrypted, making network‑based detection more difficult.
Security researchers note that the use of a fake Cloudflare CAPTCHA is a novel social‑engineering twist, exploiting the trust many users place in the familiar security widget. By embedding the malicious command in what appears to be a routine verification step, the campaign sidesteps the usual caution users apply to unfamiliar command prompts.
Microsoft recommends that organizations educate users about unexpected CAPTCHA prompts, restrict the use of Windows Terminal and PowerShell to authorized personnel, and employ endpoint detection and response solutions that monitor for unusual command‑line activity. The company also urges the deployment of updated web‑filtering rules to block known malicious domains associated with TerminalFix. As the threat landscape continues to evolve, the emergence of TerminalFix underscores the importance of combining user awareness with technical controls to thwart increasingly sophisticated phishing‑style attacks.
Comments (0)
Be the first to comment.
Join the discussion