TerminalFix Campaign Uses Reverse Tunnel for Network Access
Summary
Microsoft Threat Intelligence has detailed a TerminalFix campaign that tricks users into pasting a fake Cloudflare verification command into Windows Terminal or PowerShell. The attack goes beyond typical ClickFix activity by using DLL sideloading, steganographic payloads, Active Directory reconnaissance, and a reverse tunnel that can give attackers persistent access into internal networks.
Introduction
Microsoft has uncovered a more advanced ClickFix-style threat called TerminalFix that targets users through compromised websites and fake Cloudflare verification prompts. For IT and security teams, this matters because the campaign can turn a single compromised endpoint into a network pivot point for deeper intrusion, lateral movement, and potential ransomware activity.
What’s new in the TerminalFix campaign
Unlike earlier ClickFix attacks that often delivered a single infostealer, TerminalFix uses a multi-stage intrusion chain designed for persistence and internal network access.
Key attack stages
- Fake Cloudflare CAPTCHA lure on compromised websites
- Users are told to paste a malicious PowerShell command into Windows Terminal or PowerShell
- The script downloads a ZIP archive to
C:\ProgramDataand launches a batch file - A legitimate signed binary, LockScreenContentServer.exe, is abused for DLL sideloading of a malicious
dui70.dll - Additional payloads are hidden in PNG images using steganography
- Persistence is established through Run registry keys and scheduled tasks
- Malware performs Active Directory reconnaissance, including domain trust enumeration and domain admin discovery
- A Python-based reverse tunnel is deployed over an encrypted WebSocket connection, enabling SOCKS-style proxy access through the victim device
Why this is important for defenders
The reverse tunnel is the most significant development in this campaign. Instead of just stealing data from one machine, the attacker can use the compromised host as a bridge into the internal network.
That creates several risks for administrators:
- Increased chance of lateral movement to servers and other endpoints
- Potential credential exposure during reconnaissance
- Greater likelihood of follow-on activity such as privilege escalation, security tool tampering, data exfiltration, or ransomware deployment
Microsoft notes that affected devices should be treated as potential network access points for the attacker, even if downstream actions have not yet been observed.
Recommended next steps
Security teams should review Microsoft’s indicators of compromise, detections, and hunting guidance for this campaign. Priority actions include:
- Investigate endpoints where users may have executed unexpected PowerShell or Windows Terminal commands
- Hunt for LockScreenContentServer.exe,
dui70.dll, suspicious scheduled tasks, and unusual files underC:\ProgramData - Review outbound connections for possible reverse tunnel or WebSocket activity
- Check for signs of Active Directory enumeration and unusual administrative discovery behavior
- Educate users that CAPTCHA or website verification prompts should never require pasting commands into Terminal or PowerShell
Bottom line
TerminalFix shows how social engineering can be combined with stealthy post-compromise techniques to create a serious enterprise threat. Organizations should prioritize user awareness, endpoint detection, and network hunting to identify compromised systems before attackers can pivot further into the environment.
Need help with Security?
Our experts can help you implement and optimize your Microsoft solutions.
Talk to an ExpertStay updated on Microsoft technologies