Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Malware Analysis
  5. TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

Scheduled Pinned Locked Moved Malware Analysis
microsoftcloudflare
1 Posts 1 Posters 1 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    Microsoft has uncovered a new twist on the ClickFix social engineering technique, which it tracks as TerminalFix. Unlike older campaigns that lure victims into the Windows Run dialog, this variant steers users toward Windows Terminal or PowerShell, making it more likely that a complex malicious command will be executed successfully.

    The attack chain relies on fake Cloudflare CAPTCHA pages that prompt users to verify they are human. Instead of a simple checkbox, the page instructs the user to copy a command and paste it into a terminal. Once pasted, the command establishes a reverse-tunnel backdoor on the system, giving the attacker remote access without requiring traditional malware files to be dropped on disk.

    • The fake CAPTCHA page mimics Cloudflare branding to appear legitimate.
    • The malicious command is obfuscated and designed to run in Windows Terminal or PowerShell.
    • The backdoor uses a reverse tunnel to connect outbound, bypassing many firewall restrictions.

    Microsoft notes that this shift from the Run dialog to full-featured terminals increases the success rate of the attack, as users are more accustomed to pasting commands in these environments. The payload itself is delivered entirely in memory, leaving fewer forensic traces on the host.

    To mitigate this threat, users should avoid pasting commands from web pages into terminals unless they fully understand the command's purpose. Organizations should also monitor for unusual outbound connections and restrict PowerShell execution policies where possible.

    Source: The Hacker News

    Has your team tested user awareness against fake CAPTCHA prompts that instruct pasting into a terminal, and what was the click-through rate?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World