# Microsoft details TerminalFix campaign using fake CAPTCHAs and reverse tunnels

_Sunday, August 30, 2026 at 3:36 AM EDT · Security · Latest · Tier 2 — Notable_

![Microsoft details TerminalFix campaign using fake CAPTCHAs and reverse tunnels — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpxriybAzLw0daA0mtL3sZd04fy8Sal4s0mrBAz2-ksjwfP2V08YK_KbCJY57hKG28Kt6gn2mKq4HFSpkG2MNvA3Oz6MhNUe77_1Nvpahn2nnCFHPpxIlp5Ix4DvAZw08qXtxt1M-4zCtSENbBkODQyP_WDp9j3PXACc0XKYk1BK1K-2Xabho1cBPqerW9/s1700-nu-rw-lo-l85-e365/cf-clickfix.jpg)

Microsoft disclosed a ClickFix variant called TerminalFix that directs victims from compromised websites to fake Cloudflare CAPTCHA pages and prompts them to run malicious PowerShell commands.

The campaign targets organizations across multiple sectors. Microsoft said the attack uses DLL sideloading, payloads hidden in PNG files, Active Directory reconnaissance and a Python-based reverse-tunnel implant. The implant can tunnel TCP traffic through an encrypted WebSocket channel and let an attacker reach hosts visible from the compromised network.

Microsoft recommended restricting PowerShell execution, monitoring DLL sideloading and enabling script-block logging.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/terminalfix-uses-fake-cloudflare.html)

---
Canonical: https://techandbusiness.org/newswire/tE689GXZ_AGjMJu-pVg43n
Retrieved: 2026-08-30T12:01:40.349Z
Publisher: Tech & Business (techandbusiness.org)
