← All articles

TerminalFix tricks users with fake CAPTCHAs into pasting a backdoor command

A social-engineering campaign dubbed TerminalFix uses fake Cloudflare CAPTCHA pages, often served from compromised websites, to trick visitors into copying and running a malicious PowerShell command in their terminal. It is a refined take on the ClickFix technique, tuned to make complex scripts run more reliably, and it deploys a reverse-tunnel backdoor through a multi-stage chain involving DLL sideloading, hiding payloads inside images, and an outbound WebSocket connection for command and control. The campaign has hit organizations across several sectors. The core deception is simple to teach against: a legitimate CAPTCHA never asks you to paste and run commands in a terminal or Run dialog.

Check
Warn users that no real CAPTCHA ever asks them to paste commands into a terminal, and treat any such prompt as an attack, closing the page and reporting it.
Affected
Users lured to compromised or malicious sites showing fake CAPTCHA verification; following the prompt to run a PowerShell command installs a reverse-tunnel backdoor that gives attackers remote access to the device.
Fix
Enforce application control and PowerShell script-block logging, monitor for anomalous outbound WebSocket traffic and DLL sideloading, restrict who can run scripts, and train users to recognize fake CAPTCHA and ClickFix lures.