bleeping-computer · Crawled Sep 1, 2026
Microsoft warns of TerminalFix attacks deploying reverse tunnels
2 IoCs
Read original article ↗
AI Summary
Microsoft has identified a new variant of ClickFix attacks dubbed TerminalFix, which uses fake Cloudflare CAPTCHA prompts on compromised websites to trick users into executing malicious PowerShell commands in Windows Terminal. The attack chain involves downloading a ZIP containing a signed executable and a malicious DLL, followed by steganographic retrieval of additional payloads from PNG images. A custom Python-based reverse-tunnel module establishes an encrypted WebSocket connection to gitnow[.]dev:443, enabling attackers to pivot into internal networks via SOCKS5-style proxying and perform reconnaissance on domain controllers, databases, and other critical systems.
AI-extracted · verify before operational use