TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
Summary
In late August 2026 researchers detailed a new social-engineering campaign, dubbed TerminalFix, that abuses the Microsoft ClickFix technique to deliver a reverse-tunnel backdoor. The campaign lures victims with fake Cloudflare CAPTCHA pages that instruct them to open the Windows Run dialog and paste a command โ a variant of the ClickFix pattern in which the "verification" step itself executes the malicious payload.
Details
TerminalFix victims who paste the supplied command download and execute a backdoor that establishes a reverse tunnel to attacker infrastructure, giving the operators interactive remote access to the compromised Windows machine. Because the reverse tunnel uses outbound connections, it can bypass perimeter filtering that blocks inbound connections. The fake CAPTCHA framing plays on user familiarity with Cloudflare's ubiquitous "verify you are human" checks, lowering suspicion at the exact moment the user is asked to run a command.
Assessment
The campaign is representative of the continued evolution of ClickFix-style lures, which have become a dominant initial-access vector because they require no exploit and no malicious attachment โ the victim executes the payload themselves. Organisations should warn users never to paste commands prompted by a CAPTCHA or "verification" page, restrict interactive logon where possible, and monitor for suspicious outbound reverse tunnels. No Australian-specific targeting has been reported.