Microsoft warns of TerminalFix attacks deploying reverse tunnels

Executive Summary

Microsoft has warned that a new variant of the ClickFix malware, called TerminalFix, is using fake Cloudflare CAPTCHA prompts on compromised websites to lure users into executing malicious PowerShell commands in Windows Terminal. The malware establishes reverse tunnels to command‑and‑control servers, enabling attackers to remotely control infected machines. The threat is active and has been observed in the wild, prompting Microsoft to advise users to avoid interacting with suspicious CAPTCHA prompts and to keep their systems patched.


Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-08-31T18:51:04+00:00 - Category: threat-intel

Original Description: A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. [...]

"Edison failed 10,000 times before he made the electric light. Do not be discouraged if you fail a few times."

— Napoleon Hill
Source: Bleeping Computer