CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Microsoft warns of TerminalFix attacks deploying reverse tunnels

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5427

As cited

Copy frozen at (site build).

threat intel

Microsoft warns of TerminalFix attacks deploying reverse tunnels

Microsoft has identified TerminalFix, a variant of ClickFix malware that exploits fake Cloudflare CAPTCHA prompts on compromised websites to deceive users into executing malicious PowerShell commands via Windows Terminal. The attack chain leverages social engineering to gain initial code execution on targeted systems.

Why it matters: Windows users visiting compromised websites are at risk of credential theft and system compromise if tricked into running obfuscated commands; organizations should educate staff on verifying CAPTCHA legitimacy and restricting PowerShell execution through policy.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Microsoft warns of TerminalFix attacks deploying reverse tunnels

Microsoft has identified TerminalFix, a variant of ClickFix malware that exploits fake Cloudflare CAPTCHA prompts on compromised websites to deceive users into executing malicious PowerShell commands via Windows Terminal. The attack chain leverages social engineering to gain initial code execution on targeted systems.

Why it matters: Windows users visiting compromised websites are at risk of credential theft and system compromise if tricked into running obfuscated commands; organizations should educate staff on verifying CAPTCHA legitimacy and restricting PowerShell execution through policy.

VendorsMicrosoftCloudflare
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary