New ClickFix campaign can deploy powerful multi-stage malware directly through Windows Terminal and PowerShell


  • Microsoft warns of TerminalFix, a campaign abusing compromised sites with fake Cloudflare CAPTCHAs
  • Victims paste malicious PowerShell commands, sideloading DLLs and deploying a Python implant
  • Implant enables encrypted reverse tunnels, giving attackers pivot access into internal networks

Security researchers from Microsoft are warning of an ongoing malicious campaign that uses compromised websites to trick users into installing a powerful backdoor.

Whenever people visited any of the tainted websites, they would see a custom overlay instructing them to complete a fake Cloudflare CAPTCHA verification by copying and running a malicious PowerShell command into Terminal, or PowerShell. Microsoft named the campaign “TerminalFix”, since it is rather similar to the classic ClickFix attack.

Source link

spot_img
spot_img

Leave a reply

Please enter your comment!
Please enter your name here