Microsoft warns of TerminalFix attacks deploying reverse tunnels

Summary

Microsoft has identified a new malware campaign called TerminalFix that leverages fake Cloudflare CAPTCHA pages on compromised websites. Victims are tricked into executing malicious PowerShell commands within Windows Terminal, which then establishes reverse tunnels for attackers.

IFF Assessment

FOE

The discovery of a new malware campaign that establishes reverse tunnels poses a direct threat to defenders by allowing attackers to gain persistent access and control.

Defender Context

Defenders should be aware of this new TerminalFix campaign, which uses social engineering via fake CAPTCHA pages to deploy malware. The establishment of reverse tunnels is a significant threat, enabling persistent attacker access and control over compromised systems.

Read Full Story →