← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 29, 2026 · 05:30via CyberPress

Microsoft Warns TerminalFix ClickFix Campaign Uses Fake CAPTCHA to Deploy Reverse Tunnel

Brief

A TerminalFix campaign, a ClickFix variant, is using fake Cloudflare CAPTCHA prompts to trick users into executing PowerShell commands that install a reverse-tunnel implant.

Documented by Microsoft, the activity targets organizations and can turn a compromised Windows device into a network pivot point for attackers. The infection begins on compromised websites that replace content with a convincing Cloudflare Turnstile-style overlay.

After a victim clicks the “Verify you are human” prompt, the site copies a malicious command to the clipboard and instructs the user to open Windows Terminal or PowerShell and paste it.

Microsoft Warns TerminalFix ClickFix Campaign

Microsoft calls the technique TerminalFix because it shifts the familiar ClickFix social-engineering pattern from the Windows Run dialog to Terminal or PowerShell.

Read more on CyberPress