Hackers Spoof Cloudflare CAPTCHA to Establish Reverse Tunnels
Microsoft analysts identified TerminalFix, a ClickFix variant used with fake Cloudflare CAPTCHA, to deploy a reverse-tunnel chain that hides code, maps organizations, and routes back to attackers. The signed program loads a nearby malicious DLL, runs multi-line scripts, gathers domain and admin data, and performs targeted ping checks. Prevention includes staff training and controls like PowerShell restrictions, script-block logging, and monitoring suspicious DLL loads, scheduled tasks, and ProgramData.