[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:terminalfix-campaign-deploys-a-reverse-tunnel-through-multistage-intrusion-mtg8or16":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":15,"article_ids":16,"ioc_summary":18,"source_urls":19,"status":21,"expires_at":22,"created_at":23,"updated_at":24,"articles":25},"c5634e18-37fc-4564-b706-204706e045a4","TerminalFix campaign deploys a reverse tunnel through multistage intrusion","terminalfix-campaign-deploys-a-reverse-tunnel-through-multistage-intrusion-mtg8or16","TerminalFix (ClickFix variant) is actively compromising organizations through fake CAPTCHA prompts that trick users into running malicious PowerShell. Attackers establish persistent reverse-tunnel access, perform AD reconnaissance, and use DLL sideloading and steganography to evade detection. This is a full-chain intrusion framework targeting network persistence.","critical","advisory",[],[13,14],"Microsoft","Cloudflare Turnstile CAPTCHA","Hunt for suspicious PowerShell execution from browser processes, DLL sideloading anomalies, and outbound reverse-tunnel connections. Block known C2 IOCs immediately and scan compromised systems for lateral movement and credential theft via AD queries.",[17],"3339377d-839e-4ef6-9e3f-e6c053b45cba",null,[20],"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F08\u002F28\u002Fterminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion\u002F","active","2026-09-01T20:05:39.763+00:00","2026-08-30T20:05:48.445766+00:00","2026-08-30T20:06:21.341376+00:00",[26],{"id":17,"title":6,"url":20}]