
A new variant of ClickFix, called TerminalFix, uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal.
Unlike typical ClickFix attacks, which often result in an infostealer malware infection, this campaign uses a multi-step infiltration chain that ultimately gives the attackers a reverse tunnel into the victim’s internal network.
TerminalFix differs from normal ClickFix attacks in that it directs users to Windows Terminal or PowerShell, allowing more complex, multi-line scripts to run successfully.
Microsoft detected the attacks in the wild, but did not observe any hands-on activity. However, researchers warn that access gained in this way can be used for lateral movement, privilege escalation, credential theft, disabling of security tools, data exfiltration, or ransomware deployment.
The infection begins with a fake CAPTCHA prompt that instructs victims to execute a PowerShell command preloaded on the clipboard as part of the supposed verification process.
.jpg)
Source: Microsoft
The command downloads a ZIP archive that contains a legitimate signed executable and a malicious DLL that decodes and runs an obfuscated payload directly in memory.
For the second stage, the threat uses steganography to hide executable files and DLL fragments in the pixel data of three PNG images. The script downloads the image files from the command and control (C2) server and reassembles the embedded disk payloads.

Source: Microsoft
Malware establishes persistence through a scheduled task and registry execution key configured to run every hour.
While active, it performs reconnaissance by looking for domain controllers, databases, backup servers, gateways, and mail systems; collection of system information; and Active Directory (AD) enumeration.
The most important component is a custom Python reverse tunnel module that connects to an output address (gitnow(.)dev:443 ) over an encrypted WebSocket supporting random SOCKS5-style TCP proxying.
This allows the attacker to instruct the compromised machine to connect to internal IP addresses, hostnames, and ports accessible by the victim.

Source: Microsoft
The reverse tunnel also supports multiplexing multiple connections over a single WebSocket, rotating realistic browser user agent strings, keep-alive, and remote shutdown.
Microsoft says this can turn the infected endpoint into a network foothold, giving the operator a route to the systems discovered during the earlier AD and network reconnaissance operation.
Researchers recommend restricting and logging PowerShell execution, monitoring “LockScreenContentServer.exe” outside of its normal path, and strengthening browser and endpoint protection.
If a compromise is confirmed, it is recommended to investigate for lateral movement and change credentials, including domain administrator credentials if accessible from the infected host.
Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.
The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.
