TerminalFix fake Cloudflare CAPTCHA reverse-tunnel campaign
Campaign
Summary
Hide ▲
Show ▼
The TerminalFix campaign is using fake Cloudflare CAPTCHA pages on compromised websites to trick users into running malicious PowerShell commands, expanding risk across multiple sectors. The lure pushes victims into Windows Terminal or PowerShell, where the payload can execute more reliably. The chain deploys a Python reverse-tunnel backdoor that grants persistent internal network access and reconnaissance capability. The intrusion path can also support data exfiltration and ransomware deployment.
Related Happenings
PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS
Malware Activity
H score29
First: 21.07.2026 12:30
Last: 21.07.2026 12:30
Sources 1
About this happening:
The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 a...
PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS
Malware ActivityAbout this happening: The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 a...
ClickFix-based TELEPUZ distribution campaign
Campaign
H score35
First: 16.07.2026 15:50
Last: 16.07.2026 15:50
Sources 1
About this happening:
The ClickFix-based TELEPUZ distribution campaign is pushing TELEPUZ through websites infected with lures, increasing the chance that victims run malicious commands and...
ClickFix-based TELEPUZ distribution campaign
CampaignAbout this happening: The ClickFix-based TELEPUZ distribution campaign is pushing TELEPUZ through websites infected with lures, increasing the chance that victims run malicious commands and...
TONResolver RAT delivered via ZIP, LNK, and PowerShell
Malware Activity
H score22
First: 30.06.2026 13:30
Last: 30.06.2026 13:30
Sources 1
About this happening:
The TONResolver malware implant was delivered through a ZIP/LNK/PowerShell chain that can establish a remote access trojan foothold and enable command execution. T...
TONResolver RAT delivered via ZIP, LNK, and PowerShell
Malware ActivityAbout this happening: The TONResolver malware implant was delivered through a ZIP/LNK/PowerShell chain that can establish a remote access trojan foothold and enable command execution. T...
Snow malware suite deployment by UNC6692
Malware Activity
H score29
First: 25.04.2026 18:07
Last: 25.04.2026 18:07
Sources 1
About this happening:
UNC6692 has deployed the Snow malware suite through social engineering, creating a stealthy path to credential theft and domain compromise. The operation uses em...
Snow malware suite deployment by UNC6692
Malware ActivityAbout this happening: UNC6692 has deployed the Snow malware suite through social engineering, creating a stealthy path to credential theft and domain compromise. The operation uses em...
MIMICRAT (aka AstarionRAT) ClickFix-delivered RAT activity
Malware Activity
H score22
First: 20.02.2026 13:55
Last: 20.02.2026 13:55
Sources 1
About this happening:
The MIMICRAT (aka AstarionRAT) malware has been disclosed as a ClickFix-delivered RAT that enables Windows token impersonation and SOCKS5 tunneling, increasing the...
MIMICRAT (aka AstarionRAT) ClickFix-delivered RAT activity
Malware ActivityAbout this happening: The MIMICRAT (aka AstarionRAT) malware has been disclosed as a ClickFix-delivered RAT that enables Windows token impersonation and SOCKS5 tunneling, increasing the...
Timeline
-
30.08.2026 10:36 2 articles · 2h ago
TerminalFix campaign targets organizations with fake Cloudflare CAPTCHAs and malicious PowerShell commands
Initial DisclosureMicrosoft disclosed TerminalFix, a new ClickFix variant that targets organizations across multiple sectors by using compromised websites to serve fake Cloudflare CAPTCHA verifications and prompt victims to run malicious PowerShell or Windows Terminal commands. The chain downloads a ZIP archive with LockScreenContentServer.exe and dui70.dll for DLL sideloading, retrieves payloads hidden in PNG images from external domains, establishes persistence through Registry Run keys and scheduled tasks, performs Active Directory reconnaissance, and deploys client.py as a Python reverse-tunnel implant that can tunnel TCP traffic through gitnow[.]dev:443.
Show sources
- TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor — thehackernews.com — 30.08.2026 10:36
- TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor — thehackernews.com — 30.08.2026 10:36