TerminalFix campaign deploys reverse tunnel through multistage intrusion
Microsoft Threat Intelligence has observed a TerminalFix campaign, a variant of ClickFix, targeting organizations across multiple industries. The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command. Unlike earlier ClickFix variants that typically deliver a single infostealer, this campaign deploys a sophisticated multi-stage attack chain combining DLL sideloading, steganographic payload extraction, extensive Active Directory reconnaissance, and a custom reverse-tunnel implant, giving the attacker persistent, network-level proxy access through the compromised host. The attack chain progresses from social engineering through payload delivery, persistence, reconnaissance, and ultimately network tunneling. Microsoft provides detections and hunting guidance.
What we know
The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command.
▤ 1 sources›
The attack chain includes DLL sideloading, steganographic payload extraction, Active Directory reconnaissance, and a custom reverse-tunnel implant.
▤ 1 sources›
Microsoft Threat Intelligence observed a TerminalFix campaign, a variant of ClickFix, targeting organizations across multiple industries.
▤ 1 sources›
The reverse tunnel provides persistent, network-level proxy access through the compromised host.
▤ 1 sources›
Microsoft provides detections and hunting guidance in the blog.
▤ 1 sources›
Microsoft Threat Intelligence reports a ClickFix variant campaign, TerminalFix, using fake CAPTCHA prompts and DLL sideloading to deploy a reverse tunnel for persistent network access.
Verified · 1 sourcesLive reports
View allComments 0
Discuss this event in persistent threads. Live chat remains separate.
No comments yet. Start the conversation.