Security researchers at Microsoft have issued a cautionary note regarding a nefarious campaign dubbed “TerminalFix.” This operation exploits compromised websites to mislead users into unwittingly installing a sophisticated backdoor on their systems.
Details of the Campaign
Upon visiting these infected sites, users encounter a deceptive overlay that prompts them to complete a fabricated Cloudflare CAPTCHA verification. This seemingly harmless task requires them to copy and execute a malicious PowerShell command in their Terminal or PowerShell interface.
- Victims’ Actions: By following these instructions, victims inadvertently sideload dynamic link libraries (DLLs) and deploy a Python implant.
- Consequences: This implant establishes encrypted reverse tunnels, granting attackers the ability to pivot into internal networks.
Microsoft’s designation of this campaign as “TerminalFix” draws a parallel to the well-known ClickFix attack, highlighting the evolving tactics employed by cybercriminals to exploit unsuspecting users.