Parasharan RaghavanSuriyaraj NatarajanSagar PatilMicrosoft

Microsoft warns of new TerminalFix attack using fake CAPTCHAs to hack Windows systems; campaign targets Windows Terminal and PowerShell

Microsoft has identified a new cyberattack named TerminalFix, which employs fake CAPTCHA pages to deceive users into installing backdoor malware. This campaign specifically targets Windows Terminal and PowerShell, allowing attackers to execute complex commands and gain persistent access to compromised systems.

ETV Bharat ETV Bharat+1 source1 September 2026 · 14:04 UTC
CuriousCats Full Story

Microsoft has uncovered a new cyberattack called TerminalFix, which utilizes fake CAPTCHA pages to trick users into executing malicious commands via Windows Terminal and PowerShell. This attack is a variant of the older ClickFix method, now designed to provide attackers with persistent access to compromised systems.123

The attack begins on compromised websites that display fake Cloudflare CAPTCHA verification pages, prompting users to run a command that downloads a ZIP archive containing both a legitimate executable and a malicious DLL. The DLL decodes an obfuscated payload, establishing a foothold on the system.4

Microsoft warns that this type of access is particularly dangerous, as it allows attackers to potentially escalate their privileges, disable security tools, and exfiltrate sensitive data. The malware includes a monitoring system that checks for new instructions from the attacker, making it more persistent and difficult to remove.

To mitigate risks, Microsoft recommends organizations restrict and log PowerShell execution, monitor for signs of DLL sideloading, and train staff to recognize fake CAPTCHA scams. Additionally, they advise turning on PowerShell script block logging to detect suspicious commands before they cause harm.

TerminalFix also employs steganography to conceal malicious components, downloading hidden executable fragments within PNG images. The malware establishes persistence through scheduled tasks and Registry Run keys, executing every hour to examine the victim's network for valuable data and systems.56

Microsoft emphasizes that organizations confirming an infection should investigate for signs of lateral movement and rotate potentially exposed credentials, including domain administrator credentials.

Key Insight
“TerminalFix is a ClickFix variant that uses steganography to hide malicious code in PNG images, establishing persistence via scheduled tasks and Registry Run keys. The malware can turn a compromised PC into a pivot point for lateral movement, privilege escalation, and ransomware deployment.”
CuriousCats studied:
1
ETV BharatETV Bharat
“Microsoft has uncovered a new cyberattack called TerminalFix, which uses fake CAPTCHA pages to trick users into installing dangerous backdoor malware.”
ETV Bharat →
2
windowsreport.com
“Microsoft , a new ClickFix variant found on compromised websites. Instead of primarily installing infostealers, the campaign creates persistent access that attackers could use to reach other systems inside a victim’s network.”
windowsreport.com →
Ask CuriousCats
What is the TerminalFix attack?
Who is targeted by this cyberattack?
How does TerminalFix exploit fake CAPTCHAs?
Are similar threats on the rise?
How does ClickFix compare with TerminalFix?
Get your CIA-level briefing,
in real time.
CuriousCats monitors the internet every minute for you and brings you the most personalized brief of videos, social media posts, news and more.
Download the App
If you liked this, you’ll love your CuriousCats brief.
News, videos, opinions and more — without the noise.
Get CuriousCats