Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Dan Driscoll: US army secretary resigns after months of tension

    September 1, 2026

    More cells being built within prisons to help tackle overcrowding

    September 1, 2026

    C.D.C. Director Challenges Pennsylvania’s Report of Two Measles Deaths

    September 1, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Dan Driscoll: US army secretary resigns after months of tension
    • More cells being built within prisons to help tackle overcrowding
    • C.D.C. Director Challenges Pennsylvania’s Report of Two Measles Deaths
    • How an $80 accessory turned my tablet from mouse pad to productivity powerhouse
    • Microsoft warns of TerminalFix attacks deploying reverse tunnels
    • Strategy splits $603 million share sale between Bitcoin purchases and STRC support
    • Five years after Saied’s power grab, Tunisia’s old grievances resurface | News
    • Defendants in Minnesota Church Protest Case Challenge Charges in Flurry of Motions
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 1
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Microsoft warns of TerminalFix attacks deploying reverse tunnels

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 1, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into executing malicious PowerShell commands in Windows Terminal.

    Unlike typical ClickFix attacks that often lead to infostealer malware infections, this campaign uses a multi-stage intrusion chain that ultimately gives attackers a reverse tunnel into the victim’s internal network.

    TerminalFix differs from normal ClickFix attacks in that it directs users to Windows Terminal or PowerShell, which enables successful execution of more complex, multi-line scripts.

    image

    Microsoft discovered the attacks in the wild but did not observe hands-on activity. However, the researchers warn that access obtained this way could be leveraged for lateral movement, privilege escalation, credential theft, disabling security tools, data exfiltration, or deploying ransomware.

    The infection begins with a fake CAPTCHA prompt that instructs victims to execute a PowerShell command preloaded into the clipboard as part of the purported verification process.

    The ClickFix step
    The ClickFix step
    Source: Microsoft

    The command downloads a ZIP archive that contains a legitimate signed executable and a malicious DLL file, which decodes and launches an obfuscated payload directly in memory.

    For the second stage, the threat actor used steganography to hide executables and DLL fragments in the pixel data of three PNG images. The script downloads the image files from the command-and-control (C2) server and reassembles the embedded payloads on the disk.

    Retrieving code from steganographic images
    Retrieving code from three steganographic images
    Source: Microsoft

    The malware establishes persistence through a scheduled task and a Registry Run key, configured to execute every hour.

    While active, it performs reconnaissance by probing for domain controllers, databases, backup servers, gateways, and mail systems; collecting system information; and enumerating Active Directory (AD).

    The most important component is a custom Python reverse-tunnel module that connects to an outbound address (gitnow[.]dev:443 ) over an encrypted WebSocket, supporting SOCKS5-style arbitrary TCP proxying.

    This allows the attacker to instruct the compromised machine to connect to internal IPs, hostnames, and ports reachable from the victim.

    Establishing a reverse-tunnel
    Establishing a reverse-tunnel
    Source: Microsoft

    The reverse-tunnel also supports multiplexing multiple connections over one WebSocket, rotating realistic browser User-Agent strings, keepalive, and remote shutdown.

    Microsoft says this can turn the infected endpoint into a network pivot, giving the operator a route to systems discovered during the earlier AD and network reconnaissance operation.

    The researchers recommend restricting and logging PowerShell execution, monitoring ‘LockScreenContentServer.exe’ outside its normal path, and hardening browsers and endpoint protections.

    If compromise is confirmed, it is advisable to investigate for lateral movement and to rotate credentials, including domain admin credentials, if accessible from the infected host.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    attacks deploying Microsoft reverse TerminalFix tunnels warns
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    What the Hugging Face Incident Teaches Security Leaders About AI Agent Access

    Cronos blockchain restarts after $74 million Tectonic exploit

    Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance

    AI could cause global economic downturn, Andrew Bailey warns G20

    Trusted Chrome, Edge extensions weaponized in supply chain campaign

    Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Dan Driscoll: US army secretary resigns after months of tension

    September 1, 2026

    More cells being built within prisons to help tackle overcrowding

    September 1, 2026

    C.D.C. Director Challenges Pennsylvania’s Report of Two Measles Deaths

    September 1, 2026

    How an $80 accessory turned my tablet from mouse pad to productivity powerhouse

    September 1, 2026
    Latest Posts

    The future of AI hinges on openness and cooperation. China and Britain can gain much by working together | Zheng Zeguang

    July 30, 2026

    Drought declared for whole of Wales amid sustained high temperatures

    July 30, 2026

    This 4,000-year-old city defied the rules of history

    July 30, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Dan Driscoll: US army secretary resigns after months of tension

    September 1, 2026

    More cells being built within prisons to help tackle overcrowding

    September 1, 2026

    C.D.C. Director Challenges Pennsylvania’s Report of Two Measles Deaths

    September 1, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.