New ClickFix campaign can deploy powerful multi-stage malware directly
through Windows Terminal and PowerShell
Date:
Tue, 01 Sep 2026 09:54:16 +0000
Description:
Microsoft is calling it "TerminalFix" and says it is used to deliver
"complex, multi-line scripts".
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Microsoft warns of TerminalFix, a campaign abusing compromised sites with fake Cloudflare CAPTCHAs Victims paste malicious PowerShell commands, sideloading DLLs and deploying a Python implant Implant enables encrypted reverse tunnels, giving attackers pivot access into internal networks Security researchers from Microsoft are warning of an ongoing malicious campaign that uses compromised websites to trick
users into installing a powerful backdoor .
Whenever people visited any of the tainted websites, they would see a custom overlay instructing them to complete a fake Cloudflare CAPTCHA verification
by copying and running a malicious PowerShell command into Terminal, or PowerShell. Microsoft named the campaign TerminalFix, since it is rather similar to the classic ClickFix attack. While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the
same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex, multi-line scripts execute successfully, the researchers explained. Latest Videos From TechRadar Watch full video here: Look for lateral movement Unlike classic ClickFix campaigns that try to deliver simple infostealers, TerminalFix tries to deploy a more complex solution. After running the command in the Terminal, the victim would receive two files - a legitimate binary, and a malicious DLL file. The binary would sideload the malicious DLL which, in turn, delivers a hidden payload called client.py.
It is a custom Python implant that creates an encrypted WebSocket connection back to the attackers and gives them SOCKS5-style proxy access into the victims internal network. You may like New malware targets Microsoft Teams users by posing as your company's IT helpdesk Experts warn Claude feature hijacked by hackers to launch major malware campaign Steam Community Profiles abused as C2 network in new WordPress malware infection campaign
In other words, the attackers are deploying a remote-access/network tunneling implant that can connect to internal machines, probe domain controllers, run commands, maintain access after reboots and ultimately use the compromised machine as a pivot point for lateral movement.
This type of intrusion is particularly dangerous because it provides
attackers with direct access to an organizations internal network through the reverse tunnel, Microsoft explained. The observed reconnaissance and reverse-tunnel capability could enable an attacker to identify and reach additional systems from a compromised host. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me
with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
Microsoft did not observe the attackers actually carrying out lateral movement, so it is difficult to say what theyre using the access for. Still, the researchers are urging caution:
Organizations should treat affected devices as potential network pivot points and investigate for lateral movement and credential exposure. In the hands-on-keyboard phase that typically follows, attackers leverage this
access to escalate privileges, disable security controls, exfiltrate
sensitive data, and deploy ransomware across the organization. The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/new-clickfix-campaign-can-deploy-powerf ul-multi-stage-malware-directly-through-windows-terminal-and-powershell
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)