Microsoft Uncovers TerminalFix Campaign Using Fake CAPTCHAs for Malware Distribution

Microsoft Uncovers TerminalFix Campaign Using Fake CAPTCHAs for Malware Distribution

First seen 3 Sep 2026, 19:58 UTC ScworldTechspothothardware.com 67.5

Article Content

Browse articles
ThreatCluster

Microsoft Threat Intelligence has identified the TerminalFix campaign, which employs fake CAPTCHA prompts to trick Windows users into executing malicious commands via PowerShell or Command Prompt. This campaign is a variant of the ClickFix attacks and targets business users, significantly increasing the likelihood of successful execution of complex scripts. Once a user runs the command, the malware establishes persistent proxy access to the compromised machine, potentially allowing attackers to infiltrate other parts of the network. The malware uses DLL sideloading and steganography techniques to hide its activities and maintain persistence. Microsoft has issued mitigation guidance, recommending restrictions on PowerShell and monitoring for suspicious command activity. The campaign poses a serious risk to organizations, particularly those with inadequate security controls and user awareness.

Key Points: • TerminalFix uses fake CAPTCHAs to deceive users into running malicious commands. • The malware establishes persistent proxy access, allowing attackers to infiltrate networks. • Microsoft recommends restricting PowerShell access and monitoring for unusual command activity.

Timeline

2026-09-02
TerminalFix campaign identified
Microsoft Threat Intelligence reported on the TerminalFix campaign using fake CAPTCHA prompts to deploy malware.
Scworld
2026-09-03
Public warning issued
Microsoft published a warning about the TerminalFix campaign, highlighting its method of tricking users into executing malicious commands.
Techspot