TerminalFix campaign uses reverse-tunnel to pivot
π‘οΈ Microsoft Threat Intelligence details a TerminalFix campaign, a ClickFix variant that lures users with a fake Cloudflare Turnstile overlay and tricks them into pasting a malicious PowerShell command into Windows Terminal or PowerShell. The command drops a ZIP with a legitimate executable and a malicious DLL that is sideloaded, then uses steganography to extract further payloads from PNG images, establishes dual persistence, performs extensive Active Directory reconnaissance, and deploys a Python-based reverse-tunnel implant for SOCKS-style network access. The chain enables persistent, network-level proxy access and increases risk of lateral movement and data or credential theft.
