As cited
Copy frozen at (site build).
threat intel
Microsoft warns of TerminalFix attacks deploying reverse tunnels
Microsoft has identified TerminalFix, a variant of ClickFix malware that exploits fake Cloudflare CAPTCHA prompts on compromised websites to deceive users into executing malicious PowerShell commands via Windows Terminal. The attack chain leverages social engineering to gain initial code execution on targeted systems.
Why it matters: Windows users visiting compromised websites are at risk of credential theft and system compromise if tricked into running obfuscated commands; organizations should educate staff on verifying CAPTCHA legitimacy and restricting PowerShell execution through policy.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Microsoft warns of TerminalFix attacks deploying reverse tunnels
Microsoft has identified TerminalFix, a variant of ClickFix malware that exploits fake Cloudflare CAPTCHA prompts on compromised websites to deceive users into executing malicious PowerShell commands via Windows Terminal. The attack chain leverages social engineering to gain initial code execution on targeted systems.
Why it matters: Windows users visiting compromised websites are at risk of credential theft and system compromise if tricked into running obfuscated commands; organizations should educate staff on verifying CAPTCHA legitimacy and restricting PowerShell execution through policy.
- Source published
- First seen by Cybersecurity Tracker