Live Feeds
● TRACKER Updated 14d ago Β· 11 sources tracked

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

Microsoft has identified TerminalFix, a ClickFix variant that deploys backdoor malware via fake Cloudflare CAPTCHA pages. The attack tricks users into executing complex, multi-line PowerShell scripts within Windows Terminal. This process initiates a multi-stage sequence that establishes a reverse tunnel into the victim's corporate network. Some attackers are distributing these lures by abusing shared ChatGPT conversation links to deliver the NetSupport RAT.

πŸŽ™οΈ

Listen to Live Briefing

Real-time synthesized voice briefing Β· Live Feeds Desk

⏱ ~2 min
Speed:
RSS Source map (11)
⚑ Key Developments & Real-Time Context
Text size:
  • βœ“ Microsoft identified the TerminalFix attack using fake CAPTCHA pages to install backdoor malware.
  • βœ“ The attack tricks victims into running malicious PowerShell commands to create a reverse tunnel into the network.
  • βœ“ TerminalFix delivers complex, multi-line scripts through Windows Terminal.
πŸ›‘οΈ Source Corroboration: 11 independent reporting domains (90% confidence) ⏱ Read time: ~2 min

What changed

Attackers are now using shared ChatGPT conversation links to deliver the NetSupport RAT via the ClickFix campaign.

Live updates

  1. TerminalFix campaign uses fake CAPTCHAs to install reverse-tunnel backdoors

    Microsoft has identified TerminalFix, a ClickFix variant that deploys backdoor malware via fake Cloudflare CAPTCHA pages. The attack tricks users into executing complex, multi-line PowerShell scripts within Windows Terminal. This process initiates a multi-stage sequence that establishes a reverse tunnel into the victim's corporate network. Some attackers are distributing these lures by abusing shared ChatGPT conversation links to deliver the NetSupport RAT.

    Why it matters

    The attack leverages social engineering to bypass traditional security by making users manually run malicious code. By using legitimate-looking CAPTCHAs and trusted platforms like ChatGPT, attackers can penetrate secure corporate environments.

    What is confirmed

    • Microsoft identified the TerminalFix attack using fake CAPTCHA pages to install backdoor malware.
    • The attack tricks victims into running malicious PowerShell commands to create a reverse tunnel into the network.
    • TerminalFix delivers complex, multi-line scripts through Windows Terminal.

    Still unconfirmed

    • Cybercriminals are abusing shared ChatGPT conversation pages to deliver NetSupport RAT.

    What to watch next

    • Identification of other legitimate platforms being used to host ClickFix lures.
    • Release of specific Indicators of Compromise for the NetSupport RAT variant used in this campaign.
    Sources used for this update (4)
    1. www.etvbharat.com β€” Microsoft Warns Of New TerminalFix Attack Using Fake CAPTCHAs To Hack Windows Systems
    2. www.csoonline.com β€” Fake Cloudflare CAPTCHA tricks victims into opening a tunnel for attackers
    3. tech.yahoo.com β€” New ClickFix campaign can deploy powerful multi-stage malware directly through Windows Terminal and PowerShell
    4. cyberpress.org β€” Hackers Abuse ChatGPT Shared Links and Fake Cloudflare CAPTCHA to Deploy NetSupport RAT
    confidence 90%
  2. TerminalFix Campaign Uses Fake Cloudflare CAPTCHAs to Deploy Backdoors

    Microsoft and other security researchers have identified a ClickFix variant called TerminalFix that targets corporate networks. The campaign uses fake Cloudflare CAPTCHA prompts on compromised websites to deceive users into executing malicious PowerShell commands within Windows Terminal. Once executed, these commands establish a reverse tunnel into the victim's network. The intrusion process involves a multistage attack that utilizes steganography and DLL sideloading to bypass security measures and maintain access to the breached systems.

    Why it matters

    This attack leverages social engineering by mimicking a trusted security service to trick users into becoming the installers of their own malware. By using reverse tunnels, attackers can bypass traditional firewall restrictions to maintain persistent remote access.

    What is confirmed

    • TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick users into running malicious PowerShell commands in Windows Terminal.
    • The TerminalFix campaign deploys a reverse tunnel through a multistage intrusion.
    • The attack utilizes DLL sideloading and steganography to breach networks.

    What to watch next

    • Identification of the specific threat actor behind the TerminalFix campaign
    • Release of Indicators of Compromise (IoCs) for the reverse tunnel infrastructure
    Sources used for this update (8)
    1. The Hacker News β€” TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
    2. Microsoft β€” TerminalFix campaign deploys a reverse tunnel through multistage intrusion
    3. which.co.uk β€” How to spot a fake Captcha – and what to do if you fall for one
    4. gbhackers.com β€” TerminalFix Uses Fake CAPTCHA, DLL Sideloading and Steganography to Breach Networks
    5. cyberpress.org β€” Microsoft Warns TerminalFix ClickFix Campaign Uses Fake CAPTCHA to Deploy Reverse Tunnel
    6. CyberSecurityNews β€” Hackers Use Fake Cloudflare CAPTCHA to Deploy Reverse Tunnel Into Corporate Networks
    7. www.bleepingcomputer.com β€” Microsoft warns of TerminalFix attacks deploying reverse tunnels
    8. thehackernews.com β€” ⚑ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
    confidence 100%
πŸ“Š

Community Sentiment: How do you assess this situation?

Voice your perspective Β· Real-time aggregated sentiment from the Live Feeds community