Skip to main content
CyberConfirmedMediumDeveloping
6.1

TerminalFix malware leverages fake Cloudflare CAPTCHA for reverse tunneling

The TerminalFix variant of the ClickFix social engineering campaign uses deceptive Cloudflare CAPTCHA prompts to trick users into executing malicious PowerShell scripts. This deployment establishes a reverse tunnel, enabling attackers to pivot and access internal network resources from the compromised host.

The Hacker Newsabout 21 hours agoengCredibility 62%View source

Score Breakdown

Mosaic Score6.1
Confidence0.9
Significance0.5
Source credibility0.6
Source

Related signals

8 found