New ClickFix campaign can deploy powerful multi-stage malware directly through Windows Terminal and PowerShell
- Microsoft warns of TerminalFix, a campaign abusing compromised sites with fake Cloudflare CAPTCHAs
- Victims paste malicious PowerShell commands, sideloading DLLs and deploying a Python implant
- Implant enables encrypted reverse tunnels, giving attackers pivot access into internal networks
Security researchers from Microsoft are warning of an ongoing malicious campaign that uses compromised websites to trick users into installing a powerful backdoor.
Whenever people visited any of the tainted websites, they would see a custom overlay instructing them to complete a fake Cloudflare CAPTCHA verification by copying and running a malicious PowerShell command into Terminal, or PowerShell. Microsoft named the campaign “TerminalFix”, since it is rather similar to the classic ClickFix attack.
“While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex, multi-line scripts execute successfully,” the researchers explained.
Latest Videos FromTechRadar
Look for lateral movement
Unlike classic ClickFix campaigns that try to deliver simple infostealers, TerminalFix tries to deploy a more complex solution. After running the command in the Terminal, the victim would receive two files – a legitimate binary, and a malicious DLL file. The binary would sideload the malicious DLL which, in turn, delivers a hidden payload called “client.py”.
It is a custom Python implant that creates an encrypted WebSocket connection back to the attackers and gives them SOCKS5-style proxy access into the victim’s internal network.
In other words, the attackers are deploying a remote-access/network tunneling implant that can connect to internal machines, probe domain controllers, run commands, maintain access after reboots and ultimately use the compromised machine as a pivot point for lateral movement.
“This type of intrusion is particularly dangerous because it provides attackers with direct access to an organization’s internal network through the reverse tunnel,” Microsoft explained. “The observed reconnaissance and reverse-tunnel capability could enable an attacker to identify and reach additional systems from a compromised host.”
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Microsoft did not observe the attackers actually carrying out lateral movement, so it is difficult to say what they’re using the access for. Still, the researchers are urging caution:
“Organizations should treat affected devices as potential network pivot points and investigate for lateral movement and credential exposure. In the hands-on-keyboard phase that typically follows, attackers leverage this access to escalate privileges, disable security controls, exfiltrate sensitive data, and deploy ransomware across the organization.”
![]()
The best antivirus for all budgets

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Source
Microsoft warns of TerminalFix, a campaign abusing compromised sites with fake Cloudflare CAPTCHAs Victims paste malicious PowerShell commands, sideloading DLLs and deploying a Python implant Implant enables encrypted reverse tunnels, giving attackers pivot access into internal networks Security researchers from Microsoft are warning of an ongoing malicious campaign that uses…
Recent Posts
- John Ternus is now the CEO of Apple
- New ClickFix campaign can deploy powerful multi-stage malware directly through Windows Terminal and PowerShell
- Overcoming the biggest blocker to AI production
- Dali’s colorful new subwoofer is designed to make its affordable 5-star stereo speakers sound even bigger and better — or to be part of a great-value, stylish home theater setup
- Roland’s new digital piano has built-in Wi-Fi that integrates with a teaching app
Archives
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023