← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 1, 2026 · 11:21via CSO Online

Fake Cloudflare CAPTCHA tricks victims into opening a tunnel for attackers

Brief

Attackers are using fake CAPTCHA prompts to trick victims into running malicious PowerShell commands as part of a multi-stage intrusion campaign that can establish persistence, conduct network reconnaissance and potentially give operators a path to deeper access within an organization.

Microsoft Threat Intelligence said a campaign it calls TerminalFix, a variant of the ClickFix technique, uses compromised websites to display a fake Cloudflare verification prompt.

Victims are tricked into copying and running a malicious PowerShell command, starting an attack chain involving DLL sideloading, payloads hidden inside PNG images, persistence, Active Directory reconnaissance and, eventually, a custom reverse-tunnel implant.

Read more on CSO Online