Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell. According to reporting by The Hacker News, this campaign targets organizations across multiple sectors by leveraging compromised websites to serve fake Cloudflare CAPTCHA verifications, prompting unsuspecting visitors to execute a malicious PowerShell command.
The attack chain is described as a sophisticated multi-stage process that utilizes DLL sideloading, steganographic payload extraction, and extensive Active Directory reconnaissance. It also deploys a custom reverse-tunnel implant that grants attackers persistent, network-level proxy access through the infected machine.
Specifically, the PowerShell command is designed to download a ZIP archive containing a legitimate binary (“LockScreenContentServer.exe”) and a rogue DLL (“dui70.dll”) to initiate a DLL sideloading attack. The sideloaded DLL retrieves next-stage payloads hidden within PNG images from external domains, establishes persistence via Registry Run keys and scheduled tasks, and deploys a Python-based reverse-tunnel command-and-control (C2) implant.
This backdoor is capable of tunneling arbitrary TCP traffic back to attacker-controlled infrastructure through an encrypted WebSocket channel, allowing the C2 server to reach any host visible from the victim’s network. The reconnaissance phase includes collecting system metadata, performing domain trust discovery, and mapping the internal network topology.
Microsoft has warned that this type of intrusion is particularly dangerous as it provides attackers with direct access to an organization’s internal network. Such access can be exploited to escalate privileges, disable security controls, exfiltrate sensitive data, and deploy ransomware, making TerminalFix a significant threat to enterprise environments.
To mitigate this threat, organizations are advised to restrict PowerShell and Run dialog execution for standard users, monitor for DLL sideloading indicators, and train employees to recognize ClickFix attacks.
Follow Cyber Warriors Middle East for further global cybersecurity developments.



