Microsoft Warns of TerminalFix Campaign Using Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell. According to reporting by The Hacker News, this campaign targets organizations across multiple sectors by leveraging compromised websites to serve fake Cloudflare CAPTCHA verifications, prompting unsuspecting visitors to execute a malicious PowerShell command.

The attack chain is described as a sophisticated multi-stage process that utilizes DLL sideloading, steganographic payload extraction, and extensive Active Directory reconnaissance. It also deploys a custom reverse-tunnel implant that grants attackers persistent, network-level proxy access through the infected machine.

Specifically, the PowerShell command is designed to download a ZIP archive containing a legitimate binary (“LockScreenContentServer.exe”) and a rogue DLL (“dui70.dll”) to initiate a DLL sideloading attack. The sideloaded DLL retrieves next-stage payloads hidden within PNG images from external domains, establishes persistence via Registry Run keys and scheduled tasks, and deploys a Python-based reverse-tunnel command-and-control (C2) implant.

This backdoor is capable of tunneling arbitrary TCP traffic back to attacker-controlled infrastructure through an encrypted WebSocket channel, allowing the C2 server to reach any host visible from the victim’s network. The reconnaissance phase includes collecting system metadata, performing domain trust discovery, and mapping the internal network topology.

Microsoft has warned that this type of intrusion is particularly dangerous as it provides attackers with direct access to an organization’s internal network. Such access can be exploited to escalate privileges, disable security controls, exfiltrate sensitive data, and deploy ransomware, making TerminalFix a significant threat to enterprise environments.

To mitigate this threat, organizations are advised to restrict PowerShell and Run dialog execution for standard users, monitor for DLL sideloading indicators, and train employees to recognize ClickFix attacks.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

EU fines Google €403 million for location data breach, mandates compliance within six months.

DUBLIN: Ireland's Data Protection Commission (DPC), representing the European Union, has imposed a hefty fine of €403 million ($462 million) on Google for violating...

CrowdStrike’s SafeMind Enhances Cyber Defense with Advanced Offensive Techniques

Revolutionizing Cyber Defense: CrowdStrike's SafeMind System In the ever-evolving landscape of cybersecurity, the ability...

Roundcube Security Advisory AV26-503 Warns of Exploited CVE-2026-48842 Vulnerability

Roundcube Security Advisory AV26-503 Warns of Exploited CVE-2026-48842 Vulnerability On May 24, 2026, Roundcube issued a critical security advisory addressing vulnerabilities in its webmail product....