TerminalFix Campaign Abuses PowerShell and Reverse Tunnels for Deep Enterprise Infiltration
The TerminalFix campaign exploits a social-engineering lure — similar to ClickFix — that tricks users into executing malicious PowerShell commands, bypassing traditional perimeter defenses by abusing a trusted, built-in system tool. Once executed, the attack establishes reverse tunnels that allow attackers to maintain persistent, covert access deep within enterprise networks, making detection and eviction significantly harder. This matters because PowerShell abuse combined with reverse tunneling can circumvent firewalls and egress controls that would normally block inbound attacker connections. The multistage nature of the chain means that without proper logging and segmentation, defenders may not detect the compromise until significant damage has been done.
Tactical Insight
Immediate actions
- Restrict or disable PowerShell for non-administrative users using AppLocker or WDAC policies.
- Block unauthorized outbound tunnel protocols (e.g., ngrok, Cloudflare Tunnel, SSH reverse tunnels) at the network perimeter.
- Hunt for suspicious PowerShell execution events in SIEM using known TerminalFix IOCs immediately.
Long-term improvements
- Enforce PowerShell Constrained Language Mode and require signed scripts across all endpoints.
- Implement network segmentation to limit lateral movement and restrict workstation-to-workstation communication.
- Conduct regular security awareness training to help employees recognize social-engineering lures like ClickFix/TerminalFix-style prompts.
Detection measures
- Enable PowerShell Script Block Logging (Event ID 4104) and forward logs to a centralized SIEM for real-time alerting.
- Deploy behavioral detection rules to identify anomalous outbound connections indicative of reverse tunnel establishment.
- Monitor for unexpected child processes spawned by browsers or office applications that invoke PowerShell or cmd.exe.