TerminalFix Malware Uses Fake CAPTCHA to Tunnel Into Corporate Networks via WebSocket
Microsoft has warned of a high-severity attack campaign called TerminalFix, disclosed on August 31, 2026, in which threat actors compromise websites to display convincing fake Cloudflare CAPTCHA pages that trick users into pasting malicious PowerShell commands into their terminals. Once executed, the malware extracts a ZIP archive, performs DLL side-loading through the legitimate LockScreenContentServer.exe, and reconstructs payloads hidden inside PNG image files using steganography. The infection establishes dual persistence via a Windows Run registry key and a 60-minute scheduled task, while also enumerating Active Directory and internal servers for reconnaissance. A Python-based reverse tunnel client then relays arbitrary TCP traffic over an encrypted WebSocket connection to an external command-and-control server, effectively turning the victim's endpoint into a pivot point into the internal network. Defenders are advised to enforce PowerShell Constrained Language Mode, block execution of known binaries from non-standard paths, and monitor for suspicious WebSocket connections to domains such as gitnow.dev.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in