As cited
Copy frozen at (site build).
threat intel
Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines
An unknown threat actor is deploying TerminalFix, a variant of ClickFix social engineering attacks that tricks users into running PowerShell commands through fake Cloudflare CAPTCHA overlays. The attack chain uses DLL sideloading, steganographic payload extraction from PNG images, and Active Directory reconnaissance to establish a custom Python-based reverse tunnel that grants attackers persistent proxy access to compromised networks. The malware maintains persistence through registry keys and scheduled tasks while avoiding detection through multi-stage obfuscation and forensic artifact removal.
Why it matters: Organizations face network compromise risk when users interact with phony CAPTCHA pages or terminal-based social engineering prompts; security teams should restrict PowerShell execution, audit the Windows Run dialog, and train staff to recognize ClickFix tactics that direct them to paste commands into terminals.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines
An unknown threat actor is deploying TerminalFix, a variant of ClickFix social engineering attacks that tricks users into running PowerShell commands through fake Cloudflare CAPTCHA overlays. The attack chain uses DLL sideloading, steganographic payload extraction from PNG images, and Active Directory reconnaissance to establish a custom Python-based reverse tunnel that grants attackers persistent proxy access to compromised networks. The malware maintains persistence through registry keys and scheduled tasks while avoiding detection through multi-stage obfuscation and forensic artifact removal.
Why it matters: Organizations face network compromise risk when users interact with phony CAPTCHA pages or terminal-based social engineering prompts; security teams should restrict PowerShell execution, audit the Windows Run dialog, and train staff to recognize ClickFix tactics that direct them to paste commands into terminals.
- Source published
- First seen by Cybersecurity Tracker