radar

ONE Sentinel

securitySecurity/THREATS/HIGH

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

sourceThe Hacker News
calendar_todayAugust 30, 2026
schedule1 min read
lightbulb

EXECUTIVE SUMMARY

TerminalFix Exploits Fake CAPTCHAs to Deploy Backdoor via Windows Terminal

Summary

Microsoft has revealed a new variant of the ClickFix malware, named TerminalFix, which uses fake Cloudflare CAPTCHAs to deceive users into executing malicious commands in Windows Terminal or PowerShell.

Key Points

  • TerminalFix is a variant of the ClickFix malware, targeting Windows Terminal and PowerShell.
  • The campaign employs fake Cloudflare CAPTCHAs to trick users.
  • Unlike traditional ClickFix campaigns, TerminalFix increases complexity by directing users to Windows Terminal.
  • The campaign aims to deploy a reverse-tunnel backdoor on the victim's system.

Analysis

The TerminalFix campaign represents an evolution in phishing tactics by leveraging fake CAPTCHAs and targeting more advanced command-line interfaces like Windows Terminal and PowerShell. This approach increases the likelihood of successful exploitation due to the complexity and perceived legitimacy of these interfaces. The use of a reverse-tunnel backdoor poses significant risks, potentially allowing attackers to gain persistent access to compromised systems.

Conclusion

IT professionals should educate users about the risks of executing commands in Windows Terminal or PowerShell without verification. Implementing security measures such as endpoint protection and user training can mitigate the risks posed by such sophisticated phishing campaigns.