Home / Aug 31, 2026 / Story
0
#2 The Hacker News general August 30, 2026 at 07:36 UTC

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

By [email protected] (The Hacker News)

AI Summary

Microsoft disclosed details of TerminalFix, a new ClickFix variant that directs victims to execute malicious commands in Windows Terminal or PowerShell rather than the traditional Run dialog, deploying a reverse-tunnel backdoor via fake Cloudflare CAPTCHA pages. The shift to Terminal/PowerShell increases attack sophistication and likelihood of success against technical users who may not recognize the lure. Defenders should monitor for unexpected PowerShell or Windows Terminal invocations spawned from browser processes.

Relevance score: 86.0/100

# More from August 31