New ClickFix campaign can deploy powerful multi-stage malware directly through Windows Terminal and PowerShell
Microsoft is calling it "TerminalFix" and says it is used to deliver "complex, multi-line scripts".
Microsoft has issued a warning regarding a new campaign known as "TerminalFix," which exploits compromised websites to deliver sophisticated malware through Windows Terminal and PowerShell. Victims who visit these sites are presented with a fake Cloudflare CAPTCHA, which requires them to copy and execute a malicious PowerShell command in their Terminal or PowerShell.
TerminalFix, similar to the well-known ClickFix attack, aims to trick users into installing a powerful backdoor on their systems. After opening the CAPTCHA overlay, users are prompted to run the malicious command, leading to the installation of two files - a legitimate binary and a malicious DLL. The legitimate binary is used to sideload the malicious DLL, which then deploys a hidden Python implant called "client.py."
This implant establishes an encrypted WebSocket connection back to the attackers, granting them SOCKS5-style proxy access to the victim's internal network. By doing so, the attackers gain remote access, enabling them to probe domain controllers, run commands, maintain access even after reboots, and ultimately serve as a pivot point for lateral movement within the compromised network.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.