New ClickFix campaign can deploy powerful multi-stage malware directly through Windows Terminal and PowerShell
- Microsoft warns of TerminalFix, a campaign abusing compromised sites with fake Cloudflare CAPTCHAs
- Victims paste malicious PowerShell commands, sideloading DLLs and deploying a Python implant
- Implant enables encrypted reverse tunnels, giving attackers pivot access into internal networks
Security researchers from Microsoft are warning of an ongoing malicious campaign that uses compromised websites to trick users into installing a powerful backdoor.
Whenever people visited any of the tainted websites, they would see a custom overlay instructing them to complete a fake Cloudflare CAPTCHA verification by copying and running a malicious PowerShell command into Terminal, or PowerShell. Microsoft named the campaign “TerminalFix”, since it is rather similar to the classic ClickFix attack.
“While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex, multi-line scripts execute successfully,” the researchers explained.
Look...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE