TerminalFix Campaign Exposes Organizations to Sophisticated Cyber Threat
A sophisticated cyberattack campaign, dubbed TerminalFix, has been discovered by Microsoft Threat Intelligence. The campaign uses compromised websites to display fake Cloudflare CAPTCHA verification overlays that trick users into executing malicious PowerShell commands.
The attack chain involves multiple stages, including DLL sideloading, steganographic payload retrieval, persistence, reconnaissance, and deployment of a custom reverse-tunnel implant.
The TerminalFix campaign is particularly dangerous because it provides attackers with direct access to an organization's internal network through the reverse tunnel. The observed reconnaissance and reverse-tunnel capability could enable an attacker to identify and reach additional systems from a compromised host.
Microsoft has shared its detailed analysis of the attack chain, including indicators of compromise, detection details, and hunting guidance to help defenders identify and respond to this threat.