#2
The Hacker News
general
August 30, 2026 at 07:36 UTC
TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
By [email protected] (The Hacker News)
AI Summary
Microsoft disclosed details of TerminalFix, a new ClickFix variant that directs victims to execute malicious commands in Windows Terminal or PowerShell rather than the traditional Run dialog, deploying a reverse-tunnel backdoor via fake Cloudflare CAPTCHA pages. The shift to Terminal/PowerShell increases attack sophistication and likelihood of success against technical users who may not recognize the lure. Defenders should monitor for unexpected PowerShell or Windows Terminal invocations spawned from browser processes.
Relevance score: 86.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →