Microsoft Warns of TerminalFix Campaign Using Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell. According to reporting by The Hacker News, this campaign targets organizations across multiple sectors by leveraging compromised websites to serve fake Cloudflare CAPTCHA verifications, prompting unsuspecting visitors to execute a malicious PowerShell command.

The attack chain is described as a sophisticated multi-stage process that utilizes DLL sideloading, steganographic payload extraction, and extensive Active Directory reconnaissance. It also deploys a custom reverse-tunnel implant that grants attackers persistent, network-level proxy access through the infected machine.

Specifically, the PowerShell command is designed to download a ZIP archive containing a legitimate binary (“LockScreenContentServer.exe”) and a rogue DLL (“dui70.dll”) to initiate a DLL sideloading attack. The sideloaded DLL retrieves next-stage payloads hidden within PNG images from external domains, establishes persistence via Registry Run keys and scheduled tasks, and deploys a Python-based reverse-tunnel command-and-control (C2) implant.

This backdoor is capable of tunneling arbitrary TCP traffic back to attacker-controlled infrastructure through an encrypted WebSocket channel, allowing the C2 server to reach any host visible from the victim’s network. The reconnaissance phase includes collecting system metadata, performing domain trust discovery, and mapping the internal network topology.

Microsoft has warned that this type of intrusion is particularly dangerous as it provides attackers with direct access to an organization’s internal network. Such access can be exploited to escalate privileges, disable security controls, exfiltrate sensitive data, and deploy ransomware, making TerminalFix a significant threat to enterprise environments.

To mitigate this threat, organizations are advised to restrict PowerShell and Run dialog execution for standard users, monitor for DLL sideloading indicators, and train employees to recognize ClickFix attacks.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Microsoft Security August 2026 Update Introduces Enhanced AI Management Tools and Threat Intelligence

As organizations increasingly integrate AI agents into their operations, the need for robust cybersecurity measures has never been more critical. The latest updates from...

TerminalFix Campaign Utilizes Fake CAPTCHA to Deploy Multi-Stage Attack and Reverse Tunnel Access

Microsoft Threat Intelligence has identified a new campaign named TerminalFix, a variant of ClickFix, which is targeting organizations across various sectors. This campaign employs...

ATF Confirms Cyberattack by Qilin Ransomware Group Targeted Investigation Data

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a cyberattack attributed to the Qilin ransomware group, which targeted investigation data. The...

Trump Administration Bans Foreign-Made Power Generation Equipment Over Cybersecurity Risks

The Trump administration has issued an executive order banning the acquisition of foreign-made technology used to manage electricity and power, citing cybersecurity risks. The...