TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

Executive Summary

Microsoft disclosed a new ClickFix variant, TerminalFix, that tricks users into running a malicious command in Windows Terminal or PowerShell. It uses fake Cloudflare CAPTCHAs to lure victims, then deploys a reverse‑tunnel backdoor, expanding the attack surface and enabling remote control.


Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-08-30T07:36:33+00:00 - Category: threat-intel

Original Description: Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell. "While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex

"He who knows, does not speak. He who speaks, does not know."

— Lao Tzu
Source: The Hacker News