CloudflareMicrosoft

TerminalFix attack uses fake Cloudflare CAPTCHA to deploy reverse tunnel into corporate networks; Microsoft warns of lateral movement risk

A new cyberattack, dubbed TerminalFix, exploits compromised websites to deploy a reverse tunnel into corporate networks using a fake Cloudflare CAPTCHA. Microsoft warns that this method poses significant risks for lateral movement and credential exposure within affected organizations.

cyberpress.org cyberpress.org+1 source31 August 2026 · 12:54 UTC
CuriousCats Full Story

TerminalFix is a sophisticated cyberattack that begins on compromised websites, displaying a convincing Turnstile CAPTCHA to trick users into executing a malicious PowerShell command. This command downloads a ZIP archive containing a legitimate executable and a malicious DLL, which is sideloaded to initiate further infection stages.12345678

The malware employs steganography to hide its payloads within PNG images, complicating network inspections. Once installed, it establishes persistence through Registry Run keys and scheduled tasks, relaunching the malicious executable every 60 minutes. The malware conducts extensive reconnaissance, gathering system information and identifying critical internal systems.91011

The most concerning aspect of TerminalFix is its custom reverse-tunnel implant, which connects to external servers and allows attackers to relay TCP traffic, effectively granting them SOCKS-style proxy access to the corporate network. This capability transforms the infected device into a pivot point for accessing internal systems that are otherwise unreachable from the internet.

Microsoft has cautioned organizations to investigate affected devices for potential lateral movement and credential exposure, although they did not observe any follow-on actions in the analyzed attack chain. The campaign combines social engineering, DLL sideloading, and advanced tunneling techniques, posing a significant threat to various industries.14

Key Insight
“The attack chain abuses DLL sideloading with a legitimate signed executable and a malicious DLL, then hides payloads in PNG images via steganography. Microsoft observed no follow-on actions but advises treating any infection as potential network-level access, not just a cleanup event.”
CuriousCats studied:
1
cyberpress.orgcyberpress.org
“The attack begins on compromised websites displaying a convincing Turnstile CAPTCHA. The page shows a “Verify you are human” prompt, Cloudflare branding, and a loading animation. When users click the verification box, a malicious PowerShell command is copied to their clipboard. They are then told to open Windows Terminal or PowerShell and paste the command to complete the fake verification. The command appears legitimate because it displays Cloudflare-themed messages, including a false confirmation that the user is not a robot. In reality, it downloads a ZIP archive, extracts it into a hidden directory under `C:\ProgramData`, and launches a batch file.”
cyberpress.org →
2
CyberSecurityNewsCyberSecurityNews
“Hackers are using a fake Cloudflare CAPTCHA to turn a routine web check into a doorway into corporate networks.”
CyberSecurityNews →
Ask CuriousCats
What is the TerminalFix attack?
How does the fake CAPTCHA work?
What role does DLL sideloading play?
Are users aware of such social engineering tactics?
Which methods are most effective against similar attacks?
Get your CIA-level briefing,
in real time.
CuriousCats monitors the internet every minute for you and brings you the most personalized brief of videos, social media posts, news and more.
Download the App
If you liked this, you’ll love your CuriousCats brief.
News, videos, opinions and more — without the noise.
Get CuriousCats