By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Microsoft Warns of TerminalFix Attacks Using Reverse Tunnels
Microsoft has issued a warning regarding a new malware campaign identified as TerminalFix, which leverages compromised websites to deliver malicious PowerShell commands through fake Cloudflare CAPTCHA prompts. This campaign targets users by presenting these deceptive prompts on websites that have been injected with malicious code. When a user interacts with the fake CAPTCHA, they are tricked into executing PowerShell commands within their Windows Terminal application. The primary objective of these commands is to download and execute a malicious payload, thereby establishing a reverse tunnel. This reverse tunnel allows attackers to gain persistent, unauthorized remote access to the victim's system. The TerminalFix campaign is a variant of the previously observed ClickFix malware, indicating an evolution in the tactics, techniques, and procedures (TTPs) employed by threat actors. The use of Windows Terminal is a notable aspect of this attack, as it represents a shift from exploiting other system components or applications. By embedding malicious commands within the legitimate Windows Terminal environment, attackers can potentially evade detection by security software that might not closely monitor terminal activity. The reverse tunnel functionality is critical for the attackers, as it enables them to bypass network security measures such as firewalls that typically block unsolicited inbound connections. Once the tunnel is established, the attackers can control the compromised machine remotely, exfiltrate sensitive data, deploy further malware, or use the system as a pivot point to attack other systems within the victim's network. Microsoft's security researchers have observed that the initial compromise of websites is often achieved through common web vulnerabilities, allowing the attackers to inject their malicious scripts. The campaign's sophistication lies in its multi-stage approach, starting with website compromise, followed by social engineering via fake CAPTCHAs, and culminating in the establishment of a covert communication channel. The threat actors behind TerminalFix are actively developing and deploying new variants, suggesting a persistent and evolving threat. Microsoft recommends that organizations and individuals implement robust security practices, including keeping software updated, employing strong endpoint detection and response (EDR) solutions, and educating users about phishing and social engineering tactics to mitigate the risk posed by such attacks. The company also advises monitoring network traffic for unusual outbound connections that could indicate the presence of a reverse tunnel. The specific details of the payload and the ultimate goals of the attackers are still under investigation, but the ability to establish persistent remote access is a significant concern for cybersecurity professionals.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.