New ClickFix campaign can deploy powerful multi-stage malware directly through Windows Terminal and PowerShell

Security researchers at Microsoft have issued a cautionary note regarding a nefarious campaign dubbed “TerminalFix.” This operation exploits compromised websites to mislead users into unwittingly installing a sophisticated backdoor on their systems.

Details of the Campaign

Upon visiting these infected sites, users encounter a deceptive overlay that prompts them to complete a fabricated Cloudflare CAPTCHA verification. This seemingly harmless task requires them to copy and execute a malicious PowerShell command in their Terminal or PowerShell interface.

  • Victims’ Actions: By following these instructions, victims inadvertently sideload dynamic link libraries (DLLs) and deploy a Python implant.
  • Consequences: This implant establishes encrypted reverse tunnels, granting attackers the ability to pivot into internal networks.

Microsoft’s designation of this campaign as “TerminalFix” draws a parallel to the well-known ClickFix attack, highlighting the evolving tactics employed by cybercriminals to exploit unsuspecting users.

Winsage
New ClickFix campaign can deploy powerful multi-stage malware directly through Windows Terminal and PowerShell