Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Microsoft warns of TerminalFix attacks deploying reverse tunnels

    August 31, 2026

    Microsoft Exchange Online outage causes email failures, auth issues

    August 31, 2026

    Chinese Fire Ant hackers turn Cisco routers into spying platforms

    August 31, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Microsoft warns of TerminalFix attacks deploying reverse tunnels
    News

    Microsoft warns of TerminalFix attacks deploying reverse tunnels

    adminBy adminAugust 31, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Microsoft warns of TerminalFix attacks deploying reverse tunnels

    A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into executing malicious PowerShell commands in Windows Terminal.

    Unlike typical ClickFix attacks that often lead to infostealer malware infections, this campaign uses a multi-stage intrusion chain that ultimately gives attackers a reverse tunnel into the victim’s internal network.

    TerminalFix differs from normal ClickFix attacks in that it directs users to Windows Terminal or PowerShell, which enables successful execution of more complex, multi-line scripts.

    image

    Microsoft discovered the attacks in the wild but did not observe hands-on activity. However, the researchers warn that access obtained this way could be leveraged for lateral movement, privilege escalation, credential theft, disabling security tools, data exfiltration, or deploying ransomware.

    The infection begins with a fake CAPTCHA prompt that instructs victims to execute a PowerShell command preloaded into the clipboard as part of the purported verification process.

    The ClickFix step
    The ClickFix step
    Source: Microsoft

    The command downloads a ZIP archive that contains a legitimate signed executable and a malicious DLL file, which decodes and launches an obfuscated payload directly in memory.

    For the second stage, the threat actor used steganography to hide executables and DLL fragments in the pixel data of three PNG images. The script downloads the image files from the command-and-control (C2) server and reassembles the embedded payloads on the disk.

    Retrieving code from steganographic images
    Retrieving code from three steganographic images
    Source: Microsoft

    The malware establishes persistence through a scheduled task and a Registry Run key, configured to execute every hour.

    While active, it performs reconnaissance by probing for domain controllers, databases, backup servers, gateways, and mail systems; collecting system information; and enumerating Active Directory (AD).

    The most important component is a custom Python reverse-tunnel module that connects to an outbound address (gitnow[.]dev:443 ) over an encrypted WebSocket, supporting SOCKS5-style arbitrary TCP proxying.

    This allows the attacker to instruct the compromised machine to connect to internal IPs, hostnames, and ports reachable from the victim.

    Establishing a reverse-tunnel
    Establishing a reverse-tunnel
    Source: Microsoft

    The reverse-tunnel also supports multiplexing multiple connections over one WebSocket, rotating realistic browser User-Agent strings, keepalive, and remote shutdown.

    Microsoft says this can turn the infected endpoint into a network pivot, giving the operator a route to systems discovered during the earlier AD and network reconnaissance operation.

    The researchers recommend restricting and logging PowerShell execution, monitoring ‘LockScreenContentServer.exe’ outside its normal path, and hardening browsers and endpoint protections.

    If compromise is confirmed, it is advisable to investigate for lateral movement and to rotate credentials, including domain admin credentials, if accessible from the infected host.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleMicrosoft Exchange Online outage causes email failures, auth issues
    admin
    • Website

    Related Posts

    News

    Microsoft Exchange Online outage causes email failures, auth issues

    August 31, 2026
    News

    Chinese Fire Ant hackers turn Cisco routers into spying platforms

    August 31, 2026
    News

    How Cyber Sleuths Tracked a Nigerian Scammer to His Doorstep

    August 31, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Our Picks

    Microsoft warns of TerminalFix attacks deploying reverse tunnels

    August 31, 2026

    Microsoft Exchange Online outage causes email failures, auth issues

    August 31, 2026

    Chinese Fire Ant hackers turn Cisco routers into spying platforms

    August 31, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.