TerminalFix Turns a Fake CAPTCHA Into Network Access
Microsoft Threat Intelligence says the TerminalFix ClickFix campaign is active, using a fake Cloudflare CAPTCHA on compromised sites to trick victims into pasting a malicious PowerShell command in Windows Terminal or PowerShell. Microsoft says that shift from the Windows Run box makes long, multi-line scripts more likely to run as intended.
The chain goes well beyond a one-off lure: the initial command downloads a ZIP file, sideloads a malicious DLL, pulls hidden payloads from PNG images, sets persistence with registry Run keys and scheduled tasks, and launches a reverse-tunnel implant. That gives the attacker encrypted TCP tunneling and internal reconnaissance from the compromised host, so the machine can become a proxy into the network instead of just an infostealer victim.
For defenders, the important point is where the compromise lands: on Windows endpoints where users can open Terminal or PowerShell, the browser lure becomes an admin-tool delivery path. Microsoft did not see the later hands-on-keyboard steps in the chain it analyzed, so the remaining question is how often this pivot is being used for follow-on access in real environments.