Fake Cloudflare CAPTCHA tricks victims into opening a tunnel for attackers
Brief
Attackers are using fake CAPTCHA prompts to trick victims into running malicious PowerShell commands as part of a multi-stage intrusion campaign that can establish persistence, conduct network reconnaissance and potentially give operators a path to deeper access within an organization.
Microsoft Threat Intelligence said a campaign it calls TerminalFix, a variant of the ClickFix technique, uses compromised websites to display a fake Cloudflare verification prompt.
Victims are tricked into copying and running a malicious PowerShell command, starting an attack chain involving DLL sideloading, payloads hidden inside PNG images, persistence, Active Directory reconnaissance and, eventually, a custom reverse-tunnel implant.
