TerminalFix Variant Exploits Fake CAPTCHAs to Deploy Backdoor
Microsoft discloses new ClickFix evolution that directs victims to Windows Terminal, bypassing traditional Run dialog defenses and increasing attack complexity.
Microsoft has identified a new social engineering variant called TerminalFix that uses fraudulent Cloudflare CAPTCHA prompts to trick users into executing malicious commands. The campaign represents an evolution of the ClickFix technique, redirecting victims to Windows Terminal or PowerShell rather than the Windows Run dialog.
The shift to terminal interfaces increases the likelihood that victims will execute complex, multi-line commands without scrutiny. Traditional ClickFix campaigns relied on the Run dialog's limited interface; TerminalFix exploits the greater flexibility of modern command-line tools to deploy more sophisticated payloads.
The attack deploys a reverse-tunnel backdoor, granting attackers persistent remote access to compromised systems. By masquerading as legitimate Cloudflare security checks, the campaign exploits user trust in widely recognized brand infrastructure. The fake CAPTCHA pages appear during routine browsing, lowering victim suspicion.
- 01IT security teams must update CAPTCHA verification training and terminal execution policies
- 02Enterprises face increased risk from social engineering targeting command-line interfaces
- 03Cloudflare brand exploitation may erode user trust in legitimate security prompts
McKesson reports cyberattack affecting third-party application
The Fortune 9 pharmaceutical distributor disclosed service degradation to regulators while investigating an incident involving an unnamed vendor platform.
Hasbro Discloses Employee Data Breach Following Earlier Cyberattack
The toy and game maker confirms personal information of employees was exposed in a breach tied to operational disruptions earlier this year.
Chinese Actor Exploits ownCloud Flaw, Steals Philippine Nuclear Records
CISA adds critical vulnerability to exploit catalog after breach at Philippine research body. Chinese-speaking threat actor weaponized file-sharing flaw.