Find notable cyber news and cases, enriched with sources, timelines, and signals.

TerminalFix fake Cloudflare CAPTCHA reverse-tunnel campaign

Campaign
First reported
Last updated
Happening score
H score 36
1 unique sources, 1 articles

Summary

Hide ▲

The TerminalFix campaign is using fake Cloudflare CAPTCHA pages on compromised websites to trick users into running malicious PowerShell commands, expanding risk across multiple sectors. The lure pushes victims into Windows Terminal or PowerShell, where the payload can execute more reliably. The chain deploys a Python reverse-tunnel backdoor that grants persistent internal network access and reconnaissance capability. The intrusion path can also support data exfiltration and ransomware deployment.

Related Happenings

PylangGhost and GolangGhost ClickFix RAT delivery on Windows and macOS

Malware Activity
H score29 First: 21.07.2026 12:30 Last: 21.07.2026 12:30 Sources 1

About this happening: The PylangGhost and GolangGhost malware operation now uses ClickFix interview portals to install remote access trojans on Windows and macOS, putting Web3 a...

ClickFix-based TELEPUZ distribution campaign

Campaign
H score35 First: 16.07.2026 15:50 Last: 16.07.2026 15:50 Sources 1

About this happening: The ClickFix-based TELEPUZ distribution campaign is pushing TELEPUZ through websites infected with lures, increasing the chance that victims run malicious commands and...

TONResolver RAT delivered via ZIP, LNK, and PowerShell

Malware Activity
H score22 First: 30.06.2026 13:30 Last: 30.06.2026 13:30 Sources 1

About this happening: The TONResolver malware implant was delivered through a ZIP/LNK/PowerShell chain that can establish a remote access trojan foothold and enable command execution. T...

Snow malware suite deployment by UNC6692

Malware Activity
H score29 First: 25.04.2026 18:07 Last: 25.04.2026 18:07 Sources 1

About this happening: UNC6692 has deployed the Snow malware suite through social engineering, creating a stealthy path to credential theft and domain compromise. The operation uses em...

MIMICRAT (aka AstarionRAT) ClickFix-delivered RAT activity

Malware Activity
H score22 First: 20.02.2026 13:55 Last: 20.02.2026 13:55 Sources 1

About this happening: The MIMICRAT (aka AstarionRAT) malware has been disclosed as a ClickFix-delivered RAT that enables Windows token impersonation and SOCKS5 tunneling, increasing the...

Timeline

  1. 30.08.2026 10:36 2 articles · 2h ago

    TerminalFix campaign targets organizations with fake Cloudflare CAPTCHAs and malicious PowerShell commands

    Initial Disclosure

    Microsoft disclosed TerminalFix, a new ClickFix variant that targets organizations across multiple sectors by using compromised websites to serve fake Cloudflare CAPTCHA verifications and prompt victims to run malicious PowerShell or Windows Terminal commands. The chain downloads a ZIP archive with LockScreenContentServer.exe and dui70.dll for DLL sideloading, retrieves payloads hidden in PNG images from external domains, establishes persistence through Registry Run keys and scheduled tasks, performs Active Directory reconnaissance, and deploys client.py as a Python reverse-tunnel implant that can tunnel TCP traffic through gitnow[.]dev:443.

    Show sources