Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
TerminalFix Exploits Fake CAPTCHAs to Install Backdoor

TerminalFix Exploits Fake CAPTCHAs to Install Backdoor

Posted on August 30, 2026 By CWS

Microsoft has unveiled a new variant of the ClickFix malware, termed TerminalFix, which deceives users into executing harmful commands within Windows Terminal or PowerShell. This method enhances the probability of running intricate multi-line scripts successfully, according to Microsoft’s security researchers.

How TerminalFix Operates

TerminalFix targets various sectors by using compromised websites to display counterfeit Cloudflare CAPTCHA verifications. These fake CAPTCHAs trick users into copying and executing malicious PowerShell commands. The attack is a complex, multi-stage process, involving DLL sideloading and steganography to extract payloads, extensive reconnaissance of Active Directory, and the installation of a custom reverse-tunnel implant for persistent network access.

The PowerShell script downloads a ZIP file containing a legitimate executable and a malicious DLL to initiate a DLL sideloading attack. This rogue DLL retrieves subsequent payloads hidden within PNG images from specific domains, ensuring the attacker’s continued presence on the infected system through registry keys and scheduled tasks.

Exploring the Backdoor Capabilities

TerminalFix’s backdoor, identified as “client.py”, is capable of tunneling TCP traffic to attacker-controlled servers via an encrypted WebSocket channel. This setup allows the attacker’s command-and-control server to access any host within the victim’s network. During reconnaissance, the malware collects system metadata, performs domain trust discoveries, enumerates domain admins, searches Active Directory users and computers, and maps the internal network topology by pinging servers.

The malware includes a persistent PowerShell loop that monitors a text file for new commands, executes them, and logs the results. This feature is particularly concerning as it provides attackers with direct access to an organization’s internal network, potentially enabling further privilege escalation and data exfiltration.

Mitigation and Prevention Strategies

Microsoft emphasizes the severity of TerminalFix, noting its potential to compromise enterprise environments by bypassing security measures and deploying ransomware. To counter this threat, organizations are advised to restrict PowerShell and Run dialog access for standard users using tools like AppLocker or Windows Application Control. Additionally, monitoring for DLL sideloading indicators and training employees about ClickFix threats can enhance security posture.

Implementing PowerShell script block logging is also crucial for detecting and analyzing obfuscated or encoded commands, providing a vital line of defense against such sophisticated intrusions.

The Hacker News Tags:AppLocker, Backdoor, ClickFix, Cybersecurity, DLL Sideloading, enterprise security, fake CAPTCHA, IT security, Malware, Microsoft, network access, PowerShell, reverse-tunnel, TerminalFix, threat mitigation

Post navigation

Previous Post: OpenAI Withdraws AI Models from Cursor Amid SpaceX Takeover
Next Post: Cyberattack Targets Claude AI with Infostealer Malware

Related Posts

Critical Linux Vulnerability Exposes Systems to Root Attacks Critical Linux Vulnerability Exposes Systems to Root Attacks The Hacker News
SonicWall Investigating Potential SSL VPN Zero-Day After 20+ Targeted Attacks Reported SonicWall Investigating Potential SSL VPN Zero-Day After 20+ Targeted Attacks Reported The Hacker News
Researchers Detail Bitter APT’s Evolving Tactics as Its Geographic Scope Expands Researchers Detail Bitter APT’s Evolving Tactics as Its Geographic Scope Expands The Hacker News
CISA Highlights Cisco, Chrome, Arista Security Flaws CISA Highlights Cisco, Chrome, Arista Security Flaws The Hacker News
AI Aids Discovery of Linux Kernel Vulnerability Exploit AI Aids Discovery of Linux Kernel Vulnerability Exploit The Hacker News
AI-Powered Scripts Exploit Active Directory Vulnerabilities AI-Powered Scripts Exploit Active Directory Vulnerabilities The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks
  • Russian Enterprises Face Threats from Cyber Groups
  • TP-Link Camera Vulnerabilities Threaten User Privacy
  • AI-Driven Data Breach Notified to Spanish Authorities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks
  • Russian Enterprises Face Threats from Cyber Groups
  • TP-Link Camera Vulnerabilities Threaten User Privacy
  • AI-Driven Data Breach Notified to Spanish Authorities

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark