bleeping-computer · Crawled Sep 1, 2026

Microsoft warns of TerminalFix attacks deploying reverse tunnels

2 IoCs
Read original article ↗

AI Summary

Microsoft has identified a new variant of ClickFix attacks dubbed TerminalFix, which uses fake Cloudflare CAPTCHA prompts on compromised websites to trick users into executing malicious PowerShell commands in Windows Terminal. The attack chain involves downloading a ZIP containing a signed executable and a malicious DLL, followed by steganographic retrieval of additional payloads from PNG images. A custom Python-based reverse-tunnel module establishes an encrypted WebSocket connection to gitnow[.]dev:443, enabling attackers to pivot into internal networks via SOCKS5-style proxying and perform reconnaissance on domain controllers, databases, and other critical systems.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
Domain gitnow[.]dev Details →
IP 443 Details →