TerminalFix campaign deploys reverse tunnel through multistage intrusion
Microsoft Threat Intelligence has observed a TerminalFix campaign, a variant of ClickFix, targeting organizations across multiple industries. The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command. Unlike earlier ClickFix variants that typically deliver a single infostealer, this campaign deploys a sophisticated multi-stage attack chain combining DLL sideloading, steganographic payload extraction, extensive Active Directory reconnaissance, and a custom reverse-tunnel implant, giving the attacker persistent, network-level proxy access through the compromised host. The attack chain progresses from social engineering through payload delivery, persistence, reconnaissance, and ultimately network tunneling. Microsoft provides detections and hunting guidance.
Comments 0
Discuss this event in persistent threads. Live chat remains separate.
What we know
The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command.
▤ 1 sources›
The attack chain includes DLL sideloading, steganographic payload extraction, Active Directory reconnaissance, and a custom reverse-tunnel implant.
▤ 1 sources›
Microsoft Threat Intelligence observed a TerminalFix campaign, a variant of ClickFix, targeting organizations across multiple industries.
▤ 1 sources›
The reverse tunnel provides persistent, network-level proxy access through the compromised host.
▤ 1 sources›
Microsoft provides detections and hunting guidance in the blog.
▤ 1 sources›
Open any source to inspect its original language, when DoseFix received it, and the claims it supports.
TerminalFix campaign deploys a reverse tunnel through multistage intrusion
microsoft.com · EN · Published · Received
No comments yet. Start the conversation.