Microsoft warns of TerminalFix attacks deploying reverse tunnels
-
A new social engineering campaign, tracked as TerminalFix, is abusing fake Cloudflare CAPTCHA prompts on compromised websites to deliver malicious PowerShell commands through Windows Terminal. Microsoft has issued a warning after observing the activity, which uses a modified version of the ClickFix technique to deploy reverse tunnels for remote access.
The attack chain begins when a user visits a legitimate site that has been injected with malicious code. The site displays a fraudulent CAPTCHA verification page, often styled to look like a Cloudflare challenge. When the user clicks the verification button, a command is copied to the clipboard, and a prompt in Windows Terminal instructs them to paste and run it. This action executes a PowerShell script that downloads and runs a payload from a remote server.
- The payload establishes a reverse tunnel to attacker-controlled infrastructure.
- This tunnel allows the operators to interact with the compromised machine as if they were on the local network.
- Microsoft notes that the campaign leverages the trust users place in CAPTCHA checks, which are normally harmless.
Once the reverse tunnel is active, attackers can perform follow-up actions, including credential harvesting, lateral movement, or deploying additional malware such as remote access trojans (RATs) or stealers. The use of legitimate Windows Terminal and PowerShell reduces the chance of triggering traditional security alerts, as these tools are commonly used by administrators.
To mitigate this threat, Microsoft recommends the following:
- Block or restrict the use of Windows Terminal and PowerShell for non-administrative users where possible.
- Enable tamper protection and real-time scanning in Microsoft Defender.
- Review and monitor for outbound connections to unknown IPs or domains, especially on ports commonly used for tunneling.
- Train users to recognize that legitimate CAPTCHA checks never require copying and running commands in a terminal.
This campaign highlights how attackers continue to repurpose known techniques like ClickFix, which was previously linked to the ClearFake cluster, to bypass user awareness. In this case, the addition of a fake Cloudflare skin adds legitimacy, and the use of reverse tunnels makes the intrusion harder to detect post-exploitation.
Source: BleepingComputer
Are your users trained to spot CAPTCHA prompts that ask them to paste commands into a terminal, or have you deployed additional policy restrictions to block this behavior?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login