[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fsLCKbzLXgeHDzrNhKYKuDsfnjys_CRX-bgFLbrSSDm8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"59b8100f-3aa1-47dd-a0fa-b8f4bccea670","terminalfix-campaign-abuses-powershell-and-reverse-tunnels-for-deep-enterprise-infiltration","c93e31e8-90fd-4f0d-baa3-51e6e19a0e07","TerminalFix Campaign Abuses PowerShell and Reverse Tunnels for Deep Enterprise Infiltration","The TerminalFix campaign exploits a social-engineering lure — similar to ClickFix — that tricks users into executing malicious PowerShell commands, bypassing traditional perimeter defenses by abusing a trusted, built-in system tool. Once executed, the attack establishes reverse tunnels that allow attackers to maintain persistent, covert access deep within enterprise networks, making detection and eviction significantly harder. This matters because PowerShell abuse combined with reverse tunneling can circumvent firewalls and egress controls that would normally block inbound attacker connections. The multistage nature of the chain means that without proper logging and segmentation, defenders may not detect the compromise until significant damage has been done.","**Immediate actions:**\n- Restrict or disable PowerShell for non-administrative users using AppLocker or WDAC policies.\n- Block unauthorized outbound tunnel protocols (e.g., ngrok, Cloudflare Tunnel, SSH reverse tunnels) at the network perimeter.\n- Hunt for suspicious PowerShell execution events in SIEM using known TerminalFix IOCs immediately.\n\n**Long-term improvements:**\n- Enforce PowerShell Constrained Language Mode and require signed scripts across all endpoints.\n- Implement network segmentation to limit lateral movement and restrict workstation-to-workstation communication.\n- Conduct regular security awareness training to help employees recognize social-engineering lures like ClickFix\u002FTerminalFix-style prompts.\n\n**Detection measures:**\n- Enable PowerShell Script Block Logging (Event ID 4104) and forward logs to a centralized SIEM for real-time alerting.\n- Deploy behavioral detection rules to identify anomalous outbound connections indicative of reverse tunnel establishment.\n- Monitor for unexpected child processes spawned by browsers or office applications that invoke PowerShell or cmd.exe.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 8: Audit Log Management","CIS Control 9: Email and Web Browser Protections","CIS Control 13: Network Monitoring and Defense","NIST SP 800-53 SI-4: System Monitoring","NIST SP 800-53 AC-3: Access Enforcement","NIST SP 800-53 SC-7: Boundary Protection","MITRE ATT&CK T1059.001: PowerShell","MITRE ATT&CK T1572: Protocol Tunneling","MITRE ATT&CK T1566: Phishing (User Execution)","NIST CSF DE.CM-1: Network Monitoring","NIST CSF PR.AT-1: Security Awareness Training","published","2026-08-31T22:21:13.281286+00:00","2026-08-31T22:21:13.202+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fwww.darkreading.com\u002Fthreat-intelligence\u002Fterminalfix-campaign-weaponizes-powershell-enterprise-attacks","terminalfix-campaign-weaponizes-powershell-for-enterprise-attacks-8af725","'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":39,"name":40,"slug":41,"description":42,"color":43},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":45,"name":46,"slug":47,"description":48,"color":49},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[]]