Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines
Next-level ClickFix wave sets off multi-stage attack chain
An unknown attacker is using TerminalFix to trick users into running malicious PowerShell commands on their computers. TerminalFix is a variant of the popular ClickFix initial access method, which tricks users into running malicious commands by promoting them with fake fixes or CAPTCHA verifications. When victims interact with a spoofed Cloudflare CAPTCHA, they unknowingly copy a fake verification command to the clipboard, which then runs a hidden PowerShell script.
This script downloads a ZIP archive, extracts a malicious DLL, and launches a legitimate Windows executable that sideloads the malicious DLL. The attacker then delivers additional payloads hidden inside PNG images through steganography. The malware establishes persistence through registry keys and scheduled tasks, conducts reconnaissance on the victim's network, and drops a custom reverse tunnel implant that gives attackers persistent access to the compromised system.
To avoid this campaign, Microsoft advises organizations to restrict PowerShell and Run dialog execution, and to train employees on identifying ClickFix tactics.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.