Fake CAPTCHAs Used to Deploy Malicious Reverse Tunnel
Microsoft has issued a warning about a new campaign called TerminalFix that uses fake Cloudflare CAPTCHA prompts to trick users into executing malicious PowerShell commands. The campaign targets organizations through compromised websites that display convincing 'Verify you are human' overlays.
The attackers use social engineering to persuade victims to copy and run attacker-provided commands, rather than exploiting browser vulnerabilities. This technique is a variation of ClickFix, where victims are instructed to execute commands to resolve fake browser errors or CAPTCHAs.
Once the victim clicks the fraudulent CAPTCHA prompt, the site copies a malicious command to the clipboard and instructs the user to open Windows Terminal or PowerShell to paste it. The command downloads a ZIP archive that extracts its contents into a concealed directory under ProgramData, starting a batch file in the background.