Security & Threat Intelligence · 29.08.2026, 05:17 UTC
TerminalFix campaign deploys a reverse tunnel through multistage intrusion
| Schweregrad | high aktiv ausgenutzt (KEV) |
|---|---|
| Kategorie | Security & Threat Intelligence |
| Quelle | Microsoft Security Blog ↗ |
| Veröffentlicht | 29.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad hoch. Sie wird laut CISA-KEV aktiv ausgenutzt und sollte priorisiert behandelt werden. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
In this article
Attack chain overviewMitigation and protection guidanceLearn more
Microsoft Threat Intelligence has observed a TerminalFix campaign, a variant of ClickFix, targeting organizations across multiple industries. The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command. While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex, multi-line scripts execute successfully. Unlike earlier ClickFix variants that typically deliver a single infostealer, this TerminalFix campaign deploys a sophisticated multi-stage attack chain that combines DLL sideloading, steganographic payload extraction, extensive Active Directory reconnaissance, and a custom reverse-tunnel implant – giving the attacker persistent, network-level proxy access through the compromised host.
Once executed, the PowerShell command masquerades as a Cloudflare verification process while downloading a ZIP archive containing a legitimate binary (LockScreenContentServer.exe) and a malicious DLL (dui70.dll) used for sideloading. The sideloaded DLL drives an elaborate second stage: downloading payloads concealed inside PNG images using steganography, establishing dual persistence through Registry Run keys and scheduled tasks, conducting thorough domain reconnaissance—including domain trust enumeration, domain …
Maßnahmen
⬇ Als MarkdownVerwandte Beiträge
- info Amazon Aurora MySQL 3.13 (compatible with MySQL 8.0.45) is generally available
- info Incremental Recommendation via Causal Models
- info LLMs for Academic Workflows: An Evaluation of Literature Reviews Generated with Short and Long Context Windows of LLMs
- info Cleartext Credential Recovery in ServiceNow