Back to advisories

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

TerminalFix (ClickFix variant) is actively compromising organizations through fake CAPTCHA prompts that trick users into running malicious PowerShell. Attackers establish persistent reverse-tunnel access, perform AD reconnaissance, and use DLL sideloading and steganography to evade detection. This is a full-chain intrusion framework targeting network persistence.

CRITICALAdvisoryAug 30, 2026
Action required
Hunt for suspicious PowerShell execution from browser processes, DLL sideloading anomalies, and outbound reverse-tunnel connections. Block known C2 IOCs immediately and scan compromised systems for lateral movement and credential theft via AD queries.
Affected products
MicrosoftCloudflare Turnstile CAPTCHA