Tuesday, 1 September 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

New ClickFix campaign can deploy powerful multi-stage malware directly through Windows Terminal and PowerShell

TechRadar ·
New ClickFix campaign can deploy powerful multi-stage malware directly through Windows Terminal and PowerShell

Microsoft warns of TerminalFix, a campaign abusing compromised sites with fake Cloudflare CAPTCHAs Victims paste malicious PowerShell commands, sideloading DLLs and deploying a Python implant Implant enables encrypted reverse tunnels, giving attackers pivot access into internal networks Security researchers from Microsoft are warning of an ongoing malicious campaign that uses compromised websites to trick users into installing a powerful backdoor .

Whenever people visited any of the tainted websites, they would see a custom overlay instructing them to complete a fake Cloudflare CAPTCHA verification by copying and running a malicious PowerShell command into Terminal, or PowerShell.

Microsoft named the campaign “TerminalFix”, since it is rather similar to the classic ClickFix attack.

“While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex, multi-line scripts execute successfully,” the researchers explained.

Look for lateral movement Unlike classic ClickFix campaigns that try to deliver simple infostealers, TerminalFix tries to deploy a more complex solution.

After running the command in the Terminal, the victim would receive two files - a legitimate binary, and a malicious DLL file.

The binary would sideload the malicious DLL which, in turn, delivers a hidden payload called “client.py”.

It is a custom Python implant that creates an encrypted WebSocket connection back to the attackers and gives them SOCKS5-style proxy access into the victim’s internal network.

In other words, the attackers are deploying a remote-access/network tunneling implant that can connect to internal machines, probe domain controllers, run commands, maintain access after reboots and ultimately use the compromised machine as a pivot point for lateral movement.

“This type of intrusion is particularly dangerous because it provides attackers with direct access to an organization’s internal network through the reverse tunnel,” Microsoft explained.

“The observed reconnaissance and reverse-tunnel capability could enable an attacker to identify and reach additional systems from a compromised host.” Microsoft did not observe the attackers actually carrying out lateral movement, so it is difficult to say what they’re using the access for.

Still, the researchers are urging caution: “Organizations should treat affected devices as potential network pivot points and investigate for lateral movement and credential exposure.

Read the full article on TechRadar ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.

More from TechRadar

See all ›

More in Technology

See all ›