Fake Cloudflare CAPTCHAs

Overview

Microsoft has uncovered a new ClickFix variant, dubbed TerminalFix, that tricks users into running malicious commands in Windows Terminal or PowerShell. Unlike earlier ClickFix campaigns that abused the Windows Run dialog, TerminalFix leverages more complex environments to increase the success rate of multi‑line script execution.

Attack Chain

  • Fake Cloudflare CAPTCHAs: Victims encounter compromised websites serving counterfeit CAPTCHA prompts.
  • Malicious PowerShell command: Users are tricked into copying and executing a script.
  • DLL sideloading: Downloads a ZIP containing LockScreenContentServer.exe and rogue dui70.dll.
  • Steganographic payloads: Next‑stage malware hidden inside PNG images from attacker domains.
  • Persistence mechanisms: Registry Run keys and scheduled tasks ensure the malware survives reboots.
  • Reverse‑tunnel implant: Deploys Python‑based backdoor (client.py) to proxy traffic via encrypted WebSocket channels.

Reconnaissance Phase

TerminalFix conducts extensive Active Directory reconnaissance to map the victim’s environment:

  • Collects system metadata.
  • Performs domain trust discovery and admin enumeration.
  • Searches AD users and computers.
  • Pings named servers to chart internal network topology.

It also installs a persistent PowerShell file‑watch loop that executes commands from a monitored text file, writing results to an output file for attacker review.

Why It’s Dangerous

  • Direct internal access: Reverse tunnel provides attackers with proxy access into corporate networks.
  • Privilege escalation: Reconnaissance enables lateral movement and admin compromise.
  • Security evasion: DLL sideloading and steganography bypass detection.
  • Ransomware potential: Access can be abused to disable defenses and deploy ransomware.

Defensive Guidance

Microsoft recommends:

  • Restrict PowerShell execution: Use AppLocker, Application Control, or Group Policy.
  • Audit or block Run dialog if not required.
  • Monitor DLL sideloading for suspicious binaries.
  • Train employees to spot fake CAPTCHA prompts.
  • Enable script block logging to detect obfuscated or encoded commands.

Expert in the Cloud Insight

TerminalFix demonstrates how attackers evolve social engineering campaigns by shifting from simple Run dialog tricks to PowerShell‑based reverse tunnels. By embedding payloads in images and exploiting DLL sideloading, they achieve stealth and persistence. The lesson is clear: user vigilance and strict execution controls are essential to stop malware that weaponizes everyday IT workflows.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.