Microsoft security researchers have identified a new campaign called TerminalFix that uses fake Cloudflare CAPTCHAs to trick users into executing malicious PowerShell commands and installing network backdoors.
Key Points
- Attackers compromise websites to display fake CAPTCHA overlays that instruct users to copy and run malicious PowerShell scripts.
- The scripts sideload a malicious DLL to deploy a Python-based implant named "client.py" on the victim's machine.
- The implant establishes an encrypted WebSocket connection, providing attackers with SOCKS5-style proxy access to internal networks.
- This technique allows attackers to bypass traditional security measures by leveraging Windows Terminal or PowerShell for complex script execution.
- Microsoft warns that the campaign enables lateral movement, reconnaissance, and potential privilege escalation within corporate environments.