TechNewsReel
Live

TerminalFix Malware Uses Fake CAPTCHAs to Build Persistent Network Tunnels

A new social engineering campaign tricks Windows users into running PowerShell scripts that deploy custom reverse tunnels for deep network penetration.

TechNewsReel Newsroom · August 31, 2026

A sophisticated new malware campaign dubbed 'TerminalFix' is leveraging fake Cloudflare CAPTCHA overlays to trick Windows users into compromising their own systems. The attack represents a significant escalation in social engineering, moving beyond simple data theft to establish persistent, high-level network access.

The intrusion begins when a victim encounters a fraudulent 'verify you are human' overlay mimicking Cloudflare's security checks. This overlay copies a malicious command directly to the user's clipboard and prompts them to execute it. Unlike previous iterations of this tactic, TerminalFix directs users to open the Windows Terminal or PowerShell to run complex, multi-stage scripts. Once executed, the campaign employs DLL sideloading by using a legitimate, signed Windows executable—LockScreenContentServer.exe—to load a malicious file named dui70.dll.

Evolution of the ClickFix Method

TerminalFix is an evolution of the 'ClickFix' attack methodology. Earlier versions of ClickFix typically targeted the Windows Run dialog to deliver basic information stealers. By shifting the target to the Windows Terminal and PowerShell, attackers can now execute more sophisticated, multi-line scripts. This transition allows for a more complex intrusion chain, including the use of steganography to hide malicious payloads within PNG images. Microsoft researchers note that the attackers delete these source images after extraction to reduce forensic artifacts and evade detection.

From Data Theft to Network Compromise

This shift in delivery and execution marks a transition from opportunistic data theft to full-scale network compromise. The final payload is a Python-based reverse-tunnel implant that connects to gitnow[.]dev:443 via a reverse WebSocket tunnel. By establishing this SOCKS-style TCP proxy, attackers gain a persistent foothold that allows them to bypass traditional perimeter defenses.

Once the tunnel is active, the attackers can perform Active Directory reconnaissance to map the internal environment. This capability enables lateral movement across a corporate network, allowing the threat actors to target high-value assets such as domain controllers, internal databases, and corporate mail systems.

What to Watch

Security teams should monitor for unusual PowerShell activity and the unexpected execution of LockScreenContentServer.exe. As the campaign evolves, the use of steganography in common image formats suggests that traditional file scanning may be insufficient. Organizations are advised to reinforce user training regarding the dangers of copying and pasting commands into terminal environments, regardless of the perceived legitimacy of the prompt.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.