Microsoft has revealed information on a new ClickFix variation called TerminalFix, which attempts to fool users into executing a malicious command in PowerShell or Windows Terminal.
According to an analysis released this week by Microsoft security researchers Sagar Patil, Suriyaraj Natarajan, and Parasharan Raghavan, TerminalFix campaigns use the same technique as traditional ClickFix campaigns but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex, multi-line scripts execute successfully.
Targeting businesses in a variety of industries, the effort uses hacked websites as a springboard to offer phony Cloudflare CAPTCHA verifications, which lead unwary website users to copy and run a malicious PowerShell command.
According to the Windows manufacturer, the attack chain is a complex multi-stage procedure that makes use of steganographic payload extraction, DLL sideloading, extensive Active Directory reconnaissance, and a specially designed reverse-tunnel implant that gives the attacker persistent, network-level proxy access through the compromised machine read more about TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
