TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
Microsoft has identified TerminalFix, a ClickFix variant that deploys backdoor malware via fake Cloudflare CAPTCHA pages. The attack tricks users into executing complex, multi-line PowerShell scripts within Windows Terminal. This process initiates a multi-stage sequence that establishes a reverse tunnel into the victim's corporate network. Some attackers are distributing these lures by abusing shared ChatGPT conversation links to deliver the NetSupport RAT.
Listen to Live Briefing
Real-time synthesized voice briefing Β· Live Feeds Desk
- β Microsoft identified the TerminalFix attack using fake CAPTCHA pages to install backdoor malware.
- β The attack tricks victims into running malicious PowerShell commands to create a reverse tunnel into the network.
- β TerminalFix delivers complex, multi-line scripts through Windows Terminal.
What changed
Attackers are now using shared ChatGPT conversation links to deliver the NetSupport RAT via the ClickFix campaign.
Live updates
-
TerminalFix campaign uses fake CAPTCHAs to install reverse-tunnel backdoors
Microsoft has identified TerminalFix, a ClickFix variant that deploys backdoor malware via fake Cloudflare CAPTCHA pages. The attack tricks users into executing complex, multi-line PowerShell scripts within Windows Terminal. This process initiates a multi-stage sequence that establishes a reverse tunnel into the victim's corporate network. Some attackers are distributing these lures by abusing shared ChatGPT conversation links to deliver the NetSupport RAT.
Why it matters
The attack leverages social engineering to bypass traditional security by making users manually run malicious code. By using legitimate-looking CAPTCHAs and trusted platforms like ChatGPT, attackers can penetrate secure corporate environments.
What is confirmed
- Microsoft identified the TerminalFix attack using fake CAPTCHA pages to install backdoor malware.
- The attack tricks victims into running malicious PowerShell commands to create a reverse tunnel into the network.
- TerminalFix delivers complex, multi-line scripts through Windows Terminal.
Still unconfirmed
- Cybercriminals are abusing shared ChatGPT conversation pages to deliver NetSupport RAT.
What to watch next
- Identification of other legitimate platforms being used to host ClickFix lures.
- Release of specific Indicators of Compromise for the NetSupport RAT variant used in this campaign.
confidence 90%Sources used for this update (4)
- www.etvbharat.com β Microsoft Warns Of New TerminalFix Attack Using Fake CAPTCHAs To Hack Windows Systems
- www.csoonline.com β Fake Cloudflare CAPTCHA tricks victims into opening a tunnel for attackers
- tech.yahoo.com β New ClickFix campaign can deploy powerful multi-stage malware directly through Windows Terminal and PowerShell
- cyberpress.org β Hackers Abuse ChatGPT Shared Links and Fake Cloudflare CAPTCHA to Deploy NetSupport RAT
-
TerminalFix Campaign Uses Fake Cloudflare CAPTCHAs to Deploy Backdoors
Microsoft and other security researchers have identified a ClickFix variant called TerminalFix that targets corporate networks. The campaign uses fake Cloudflare CAPTCHA prompts on compromised websites to deceive users into executing malicious PowerShell commands within Windows Terminal. Once executed, these commands establish a reverse tunnel into the victim's network. The intrusion process involves a multistage attack that utilizes steganography and DLL sideloading to bypass security measures and maintain access to the breached systems.
Why it matters
This attack leverages social engineering by mimicking a trusted security service to trick users into becoming the installers of their own malware. By using reverse tunnels, attackers can bypass traditional firewall restrictions to maintain persistent remote access.
What is confirmed
- TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick users into running malicious PowerShell commands in Windows Terminal.
- The TerminalFix campaign deploys a reverse tunnel through a multistage intrusion.
- The attack utilizes DLL sideloading and steganography to breach networks.
What to watch next
- Identification of the specific threat actor behind the TerminalFix campaign
- Release of Indicators of Compromise (IoCs) for the reverse tunnel infrastructure
confidence 100%Sources used for this update (8)
- The Hacker News β TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
- Microsoft β TerminalFix campaign deploys a reverse tunnel through multistage intrusion
- which.co.uk β How to spot a fake Captcha β and what to do if you fall for one
- gbhackers.com β TerminalFix Uses Fake CAPTCHA, DLL Sideloading and Steganography to Breach Networks
- cyberpress.org β Microsoft Warns TerminalFix ClickFix Campaign Uses Fake CAPTCHA to Deploy Reverse Tunnel
- CyberSecurityNews β Hackers Use Fake Cloudflare CAPTCHA to Deploy Reverse Tunnel Into Corporate Networks
- www.bleepingcomputer.com β Microsoft warns of TerminalFix attacks deploying reverse tunnels
- thehackernews.com β β‘ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
Community Sentiment: How do you assess this situation?
Voice your perspective Β· Real-time aggregated sentiment from the Live Feeds community