Back Theregister Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines
security Researcher shows how Claude Code can be tricked simply by asking it to summarize a website
Researcher shows how Claude Code can be tricked simply by asking it to summarize a website
science German-Japanese researchers invent electricity-free tech that could cool datacenters
German-Japanese researchers invent electricity-free tech that could cool datacenters
Legal Nuisance-call blocker fined £190k for being a nuisance caller
Nuisance-call blocker fined £190k for being a nuisance caller
NETWORKS A lot of datacenter networks are run by absolute clowns. Not Amazon's
A lot of datacenter networks are run by absolute clowns. Not Amazon's
security Security vets rally around $4 paper password books for sale in Australia
Security vets rally around $4 paper password books for sale in Australia
An unknown miscreant is using "TerminalFix" to trick unsuspecting users into running PowerShell commands that infect their computers with a reverse tunnel granting attackers access to their networks. Some of the malware is even hidden inside PNG graphics the PC downloads.
TerminalFix is the latest variant of the wildly popular ClickFix initial access method for attackers. This type of social engineering technique tricks users into running malicious commands by promoting them with a phony fix or CAPTCHA verification.
While traditional ClickFix attacks point victims to the Windows Run dialog, TerminalFix directs users to Windows Terminal or PowerShell, which increases the likelihood that they will unknowingly run multi-line scripts on their own computers, Redmond says .
Plus, instead of delivering just one infostealer, this campaign kicks off a multi-stage attack chain that combines DLL sideloading, steganographic payload extraction, and Active Directory reconnaissance. It ultimately deploys a custom reverse tunnel on the infected machine that gives the attacker persistent, network-level proxy access through the compromised device.
Microsoft declined to answer The Register ’s questions, including how many organizations were targeted and victimized in this TerminalFix campaign, and which attacker or criminal crew is responsible for these attacks.
The attack chain begins when the victim interacts with a phony overlay that spoofs the Cloudflare CAPTCHA “verify you are human” checkbox and includes a Cloudflare logo, causing a fake verification command to be copied to the clipboard before the victim pastes it into Windows Terminal or PowerShell.
This command runs a hidden PowerShell script that prints a fake “Starting Cloudflare verification…” message and downloads a ZIP archive from an attacker-controlled server. It extracts the archive under C:\ProgramData and launches a batch file (1.bat) that silently executes LockScreenContentServer.exe.
LockScreenContentServer.exe is a legitimate, signed Windows executable - and it acts as the DLL sideloading host for a second file: dui70.dll. This purports to be a “Windows DirectUI Engine,” but is actually the malicious payload, which executes a second-stage PowerShell script once it’s sideloaded.
The second PowerShell script downloads additional payloads hidden inside PNG images - this is called steganography, and it makes file- and content-type inspection more difficult, and thus easier to hide malicious payloads. In an attempt to further obfuscate the payload and avoid being detected, the attacker split the payload into multiple PNGs.
The PowerShell script downloads the three images, extracts an executable from the first image and two halves of the DLL from the second and third images, and then reassembles the components on disk.
“After extraction, the source images are deleted to reduce forensic artifacts,” Microsoft researchers Sagar Patil, Suriyaraj Natarajan, and Parasharan Raghavan wrote.
The malware establishes redundant persistence through both HKCU\…\Run registry keys and scheduled tasks that re-execute LockScreenContentServer.exe every 60 minutes to ensure it survives reboots.
It then does reconnaissance on the compromised machine, scooping up system information across multiple language configurations including English, Spanish, and German. It also performs domain trust discovery, domain admin enumeration, and Active Directory user and computer searches, while pinging targeted, named servers.
“The observed names correspond to common infrastructure roles, including domain controllers, databases, backup, gateways, and mail systems,” according to the threat hunters. “This probing could help an attacker identify accessible target systems for follow-on activity.”
, the malware drops a persistent PowerShell file-watch loop that monitors a text file for new commands, executes them via Invoke-Expression, and writes results to an output file. This allows the attacker to execute additional PowerShell commands by writing them to the text file.
And finally, the attacker deploys a custom, Python-based reverse-tunnel implant. The tunnel launches with no visible window via pythonw.exe, and it sets up a reverse WebSocket tunnel to gitnow[.]dev:443. This implant, combined with earlier reconnaissance data, gives the attacker SOCKS-style TCP proxy access through the victim’s network.
Microsoft recommends organizations take several steps to avoid becoming a victim of this campaign. These include restricting PowerShell and Run dialog execution, and either blocking or auditing the Windows Run dialog (Win+R) if it’s not needed for daily work.
Also, train employees on how to look for ClickFix tactics, like fake CAPTCHA verification pages that tell them to paste commands into Terminal or the Run dialog. ®
Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines
-level ClickFix wave sets off multi-stage attack chain
Broadcom pledges to lock down open source Python, Java libraries
Promises ‘secure artifacts’ for Spring and RabbitMQ, and other projects that matter to its Tanzu suite
Platform Engineering 2.0: your platform was built for a different era. AI just exposed it
PARTNER CONTENT: Platform engineering won the argument. Now it has to grow up fast and evolve for the AI era.
Anthropic cracks down on hijacked user accounts mining AI tokens
Commodity malware steals authenticated sessions, letting thieves freeload on victims' paid usage
A lot of datacenter networks are run by absolute clowns. Not Amazon's
AWS keeps customer costs down in part through networking advances
From watches to passwords on paper, everything that's old is new again
This week on the Kettle, we reminisce the good old days of Windows on XP's 25th anniversary, how new-old Casio watches could reshape the smartwatch market, and why passwords might be better on paper
security Researcher shows how Claude Code can be tricked simply by asking it to summarize a website
Researcher shows how Claude Code can be tricked simply by asking it to summarize a website
security Security vets rally around $4 paper password books for sale in Australia
Security vets rally around $4 paper password books for sale in Australia
science German-Japanese researchers invent electricity-free tech that could cool datacenters
German-Japanese researchers invent electricity-free tech that could cool datacenters
Legal Nuisance-call blocker fined £190k for being a nuisance caller
Nuisance-call blocker fined £190k for being a nuisance caller
AI and ml Apple defies memory shortage with new Mac minis
Apple defies memory shortage with new Mac minis
Security AliExpress accused of fingerprinting shoppers with silent audio trick that also muted a dev's headphones
AliExpress accused of fingerprinting shoppers with silent audio trick that also muted a dev's headphones
ai and ml Energy biz SSE smacked around in court by a guy and AI Company's three year pursuit of debt from non-existent address ended by Oxford judge
Energy biz SSE smacked around in court by a guy and AI
Company's three year pursuit of debt from non-existent address ended by Oxford judge
security Industry that built the problem offers to sell you the solution 100+ tech giants warn AI attacks are coming, skip the part where they pay for defenses
Industry that built the problem offers to sell you the solution
100+ tech giants warn AI attacks are coming, skip the part where they pay for defenses
SYSTEMS Nvidia and Cerebras are selling performance their customers will (probably) never see Touting batch 1 token generation is a bit like boasting the top speed of your car
Nvidia and Cerebras are selling performance their customers will (probably) never see
Touting batch 1 token generation is a bit like boasting the top speed of your car
software Google forces Android apps to use memory more wisely as RAMpocalypse rages No one can afford RAM anymore, so we're requiring devs to mind memory usage
Google forces Android apps to use memory more wisely as RAMpocalypse rages
No one can afford RAM anymore, so we're requiring devs to mind memory usage
personal tech HP has a solution to expensive AI tokens: Buy a more expensive PC Rising cloud AI costs are pushing workloads onto pricier PCs – which just happen to be better for PC maker's margins
HP has a solution to expensive AI tokens: Buy a more expensive PC
Rising cloud AI costs are pushing workloads onto pricier PCs – which just happen to be better for PC maker's margins
Security Russians are posing as Signal support to launch phishing attacks PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Russians are posing as Signal support to launch phishing attacks
PLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more!
Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attack
PLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more
Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructure Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Black Hat and DEF CON
DEF CON Franklin project enlists hackers to harden critical infrastructure
Voting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included
Security EQT buys majority in Swiss cybersecurity biz Acronis Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
EQT buys majority in Swiss cybersecurity biz Acronis
Went at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified
Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight On the plus side, infosec's a good bet for a long, stable career
Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sight
On the plus side, infosec's a good bet for a long, stable career
Debian votes to let contributors code with AI Disclosure optional, quality mandatory
Debian votes to let contributors code with AI
Disclosure optional, quality mandatory
LibreOffice 26.8 is out – local first, and with no AI It looks a bit clunky, but it does the job – and on your own computer
LibreOffice 26.8 is out – local first, and with no AI
It looks a bit clunky, but it does the job – and on your own computer
Keepers of Noble Numbats to be offered a Resolute Racoon: Ubuntu 26.04.1 is coming GRUB's up for furry new update
Keepers of Noble Numbats to be offered a Resolute Racoon: Ubuntu 26.04.1 is coming
GRUB's up for furry new update
AROS, the FOSS recreation of AmigaOS, comes to Raspberry Pi Plus: new official Amiga-branded hardware is coming
AROS, the FOSS recreation of AmigaOS, comes to Raspberry Pi
Plus: new official Amiga-branded hardware is coming
Emperor Penguin Linus Torvalds banishes a bug – with a bot The lad himself finds and fixes a tricky one… or does he?
Emperor Penguin Linus Torvalds banishes a bug – with a bot
The lad himself finds and fixes a tricky one… or does he?
FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash another Word up
FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash another
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
