TerminalFix Campaign Exploits Fake Cloudflare CAPTCHAs for Reverse Tunneling

TerminalFix Campaign Exploits Fake Cloudflare CAPTCHAs for Reverse Tunneling

First seen 30 Aug 2026, 09:14 UTC GbhackersThehackernews 63.0

Article Content

Browse articles
ThreatCluster

The TerminalFix campaign has been identified using fraudulent Cloudflare CAPTCHA prompts to deceive users into executing harmful PowerShell commands. This tactic converts compromised Windows devices into reverse-tunnel pivot points for attackers. Microsoft has confirmed that the campaign targets organizations through compromised websites that display a convincing overlay mimicking Cloudflare's 'Verify you are human' CAPTCHA. The attack primarily affects Windows systems, with no specific numbers of affected organizations reported. The current status of the campaign indicates ongoing exploitation, as users are tricked into executing the malicious commands. Organizations are advised to remain vigilant against such deceptive tactics.

Key Points: • TerminalFix uses fake Cloudflare CAPTCHAs to deploy malicious PowerShell commands. • The campaign targets Windows devices, turning them into reverse-tunnel points for attackers. • Microsoft has confirmed the ongoing exploitation of this tactic against organizations.

Timeline

2026-08-29
TerminalFix campaign documented
Microsoft reported on the TerminalFix campaign using fake Cloudflare CAPTCHAs to deploy malicious commands on Windows devices.
Gbhackers
2026-08-30
Further details published
The Hacker News provided additional insights into the TerminalFix campaign and its exploitation methods.
Thehackernews