DoseFix LIVE
0votes
Cyber Security·Global·CONFIRMED

TerminalFix campaign deploys reverse tunnel through multistage intrusion

Global·
DoseFix EditorialMulti-source synthesis

Microsoft Threat Intelligence has observed a TerminalFix campaign, a variant of ClickFix, targeting organizations across multiple industries. The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command. Unlike earlier ClickFix variants that typically deliver a single infostealer, this campaign deploys a sophisticated multi-stage attack chain combining DLL sideloading, steganographic payload extraction, extensive Active Directory reconnaissance, and a custom reverse-tunnel implant, giving the attacker persistent, network-level proxy access through the compromised host. The attack chain progresses from social engineering through payload delivery, persistence, reconnaissance, and ultimately network tunneling. Microsoft provides detections and hunting guidance.

1 sources
Global

Comments 0

Discuss this event in persistent threads. Live chat remains separate.

Keep discussion civil and distinguish opinion from verified information.

No comments yet. Start the conversation.

What we know

The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command.

1 sources

The attack chain includes DLL sideloading, steganographic payload extraction, Active Directory reconnaissance, and a custom reverse-tunnel implant.

1 sources

Microsoft Threat Intelligence observed a TerminalFix campaign, a variant of ClickFix, targeting organizations across multiple industries.

1 sources

The reverse tunnel provides persistent, network-level proxy access through the compromised host.

1 sources

Microsoft provides detections and hunting guidance in the blog.

1 sources
Source transparency

Open any source to inspect its original language, when DoseFix received it, and the claims it supports.

Microsoft Security Blog

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

microsoft.com · EN · Published · Received
Independent

Live reports

View all
TerminalFix campaign analysisLocal voice · Global
Verified
TerminalFix campaign deploys reverse tunnel through multistage intrusion | DoseFix