TerminalFix Attacks Use Fake CAPTCHAs To Secretly Hack Windows PCs
Microsoft Threat Intelligence has discovered a new variant of the ClickFix malware campaign we covered last year, and it's been dubbed "TerminalFix." The fundamental nature of the attack is similar in the sense that it also relies on false CAPTCHAs that impersonate Cloudflare or other reputable providers. ClickFix typically deploys a single infostealer after prompting users to launch the Windows Run dialog, while TerminalFix instead directs users to PowerShell or a command prompt.
TerminalFix is more dangerous because it increases "the likelihood that complex, multi-line scripts execute successfully."
The goal TerminalFix is to deploy a multi-stage attack that ultimately gives the attacker persistent, network-level proxy access through the compromised host. If targeted properly at an unsecured enterprise network, TerminalFix could result in substantial data theft and malware spreading through the network from the first infected machine. From there, attackers can either subtly exfiltrate sensitive data or go as far as...
Copyright of this story solely belongs to hothardware.com. To see the full text click HERE