TechNewsReel
Live

Microsoft Warns of TerminalFix Malware Using Fake Cloudflare CAPTCHAs

A new variant of the ClickFix campaign tricks users into executing malicious PowerShell commands to establish remote backdoors.

TechNewsReel Newsroom · August 30, 2026

Microsoft has identified a new malware variant dubbed TerminalFix, which leverages social engineering to compromise Windows systems. The campaign uses fraudulent Cloudflare CAPTCHAs to deceive users into manually executing malicious code on their own machines.

TerminalFix is a variant of the broader ClickFix campaign. The attack begins when a victim encounters a fake Cloudflare Turnstile verification page. Instead of a standard CAPTCHA, the site instructs the user to copy a specific string of text and execute it within Windows Terminal or PowerShell. Once run, the payload establishes a reverse-tunnel backdoor, granting attackers remote access to the infected system.

Evolution of the ClickFix Lure

ClickFix campaigns have historically relied on "browser error" or "verification" lures to convince users to run commands that download malware. Previous iterations of these attacks typically targeted the Windows Run dialog, which has limited capabilities for complex scripting. TerminalFix evolves this strategy by directing victims toward more powerful shell environments, specifically PowerShell and Windows Terminal, which allow for the execution of more sophisticated malicious scripts.

Implications for System Security

Moving the attack vector from the simple Run dialog to full shell environments significantly increases the risk to the end user. By utilizing PowerShell, attackers can deploy more complex payloads and maintain persistent access via reverse tunnels. This method is particularly dangerous because it bypasses traditional perimeter defenses, as the connection is initiated from inside the network, increasing the likelihood of a full system compromise.

Monitoring the Threat

Security researchers continue to monitor the evolution of the ClickFix ecosystem as attackers refine their social engineering tactics. While the use of fake CAPTCHAs is a known vector, the shift toward targeting advanced shell environments suggests a move toward more persistent and harder-to-detect intrusions. Organizations are encouraged to monitor for unauthorized PowerShell execution and unusual outbound network tunnels to mitigate the risk of these sophisticated social engineering attacks.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.