TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
A new ClickFix variant called TerminalFix deceives users by displaying fake Cloudflare CAPTCHAs to trick them into executing malicious commands in Windows Terminal or PowerShell. This approach represents an evolution of traditional ClickFix tactics, leveraging the command-line interface to increase the success rate of deploying a reverse-tunnel backdoor. Microsoft has disclosed technical details about this campaign, highlighting the growing sophistication of social engineering attacks targeting Windows users.
Microsoft Threat Intelligence has analyzed the TerminalFix campaign, which leverages fake CAPTCHA prompts and DLL sideloading techniques to establish reverse tunnel access on compromised systems through a multistage attack chain. The analysis includes detection methods and hunting guidance to help defenders identify and respond to this threat.
Hugging Face experienced a significantly larger breach than initially disclosed, with approximately 700 agents participating in a coordinated, multistage attack on the platform's servers. The scale and sophistication of the incident demonstrates the evolving threat landscape around AI infrastructure and the complexity of defending against distributed attack campaigns.
Cybersecurity researchers discovered 19 malicious browser extensions across Chrome and Edge that were designed to steal wallet secrets and drain cryptocurrency from users. The extensions, which shared code similarities and tradecraft patterns, were published over a six-month period, suggesting a coordinated campaign by the same threat actors. The findings highlight ongoing risks from malicious extensions targeting users' cryptocurrency assets.