TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

Cybersecurity · August 31, 2026

Cybersecurity·thehackernews.com

Microsoft has detailed a new social-engineering campaign called TerminalFix that lures victims with a spoofed Cloudflare CAPTCHA page and then walks them through pasting a command into Windows Terminal or PowerShell. Unlike earlier ClickFix-style attacks that targeted the simpler Windows Run dialog, this variant pushes victims toward a full terminal, letting attackers execute more complex commands and ultimately install a reverse-tunnel backdoor for persistent remote access.

// source: thehackernews.com ↗

Back to Blog