AUTO-UPDATED

New ClickFix campaign can deploy powerful multi-stage malware directly through Windows Terminal and PowerShell

Microsoft security researchers have identified a new campaign called TerminalFix that uses fake Cloudflare CAPTCHAs to trick users into executing malicious PowerShell commands and installing network backdoors.

Key Points

  • Attackers compromise websites to display fake CAPTCHA overlays that instruct users to copy and run malicious PowerShell scripts.
  • The scripts sideload a malicious DLL to deploy a Python-based implant named "client.py" on the victim's machine.
  • The implant establishes an encrypted WebSocket connection, providing attackers with SOCKS5-style proxy access to internal networks.
  • This technique allows attackers to bypass traditional security measures by leveraging Windows Terminal or PowerShell for complex script execution.
  • Microsoft warns that the campaign enables lateral movement, reconnaissance, and potential privilege escalation within corporate environments.

Why it Matters

This campaign represents a significant escalation in social engineering tactics by providing attackers with persistent, remote access to internal network infrastructure. Organizations must treat compromised devices as critical security risks, as this level of access often serves as a precursor to data exfiltration or ransomware deployment.
TechRadar Published by Sead Fadilpašić
Read original