CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5879

As cited

Copy frozen at (site build).

threat intel

Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines

An unknown threat actor is deploying TerminalFix, a variant of ClickFix social engineering attacks that tricks users into running PowerShell commands through fake Cloudflare CAPTCHA overlays. The attack chain uses DLL sideloading, steganographic payload extraction from PNG images, and Active Directory reconnaissance to establish a custom Python-based reverse tunnel that grants attackers persistent proxy access to compromised networks. The malware maintains persistence through registry keys and scheduled tasks while avoiding detection through multi-stage obfuscation and forensic artifact removal.

Why it matters: Organizations face network compromise risk when users interact with phony CAPTCHA pages or terminal-based social engineering prompts; security teams should restrict PowerShell execution, audit the Windows Run dialog, and train staff to recognize ClickFix tactics that direct them to paste commands into terminals.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines

An unknown threat actor is deploying TerminalFix, a variant of ClickFix social engineering attacks that tricks users into running PowerShell commands through fake Cloudflare CAPTCHA overlays. The attack chain uses DLL sideloading, steganographic payload extraction from PNG images, and Active Directory reconnaissance to establish a custom Python-based reverse tunnel that grants attackers persistent proxy access to compromised networks. The malware maintains persistence through registry keys and scheduled tasks while avoiding detection through multi-stage obfuscation and forensic artifact removal.

Why it matters: Organizations face network compromise risk when users interact with phony CAPTCHA pages or terminal-based social engineering prompts; security teams should restrict PowerShell execution, audit the Windows Run dialog, and train staff to recognize ClickFix tactics that direct them to paste commands into terminals.

VendorsMicrosoftCloudflare
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary