Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-31 ยท updated: 2026-08-31 ยท tags: [incident, campaign, malware, backdoor, phishing, social-engineering, credential-theft] ยท confidence: medium ยท severity: medium ยท affected_sectors: [technology] ยท au_impact: false

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

Summary

In late August 2026 researchers detailed a new social-engineering campaign, dubbed TerminalFix, that abuses the Microsoft ClickFix technique to deliver a reverse-tunnel backdoor. The campaign lures victims with fake Cloudflare CAPTCHA pages that instruct them to open the Windows Run dialog and paste a command โ€” a variant of the ClickFix pattern in which the "verification" step itself executes the malicious payload.

Details

TerminalFix victims who paste the supplied command download and execute a backdoor that establishes a reverse tunnel to attacker infrastructure, giving the operators interactive remote access to the compromised Windows machine. Because the reverse tunnel uses outbound connections, it can bypass perimeter filtering that blocks inbound connections. The fake CAPTCHA framing plays on user familiarity with Cloudflare's ubiquitous "verify you are human" checks, lowering suspicion at the exact moment the user is asked to run a command.

Assessment

The campaign is representative of the continued evolution of ClickFix-style lures, which have become a dominant initial-access vector because they require no exploit and no malicious attachment โ€” the victim executes the payload themselves. Organisations should warn users never to paste commands prompted by a CAPTCHA or "verification" page, restrict interactive logon where possible, and monitor for suspicious outbound reverse tunnels. No Australian-specific targeting has been reported.