LIVE · cybersecurity feed
Live wire
malwarehigh

New Malware Uses Fake CAPTCHAs to Deploy Backdoor

A new malware variant, identified as TerminalFix, has been discovered by Microsoft. This malicious software tricks users into executing harmful commands through Windows Terminal or PowerShell by presenting fake Cloudflare CAPTCHAs. Unlike previous versions that targeted the Run dialog, this variant's use of the command line interface may increase its success rate.

zeroday.news ·

A newly identified malware variant, dubbed TerminalFix by Microsoft, has been observed leveraging deceptive Cloudflare CAPTCHAs to trick users into executing malicious commands. This particular variant is notable for its method of operation, which involves manipulating users into running harmful instructions through Windows Terminal or PowerShell.

The core mechanism of TerminalFix relies on social engineering, specifically by presenting what appears to be a legitimate Cloudflare CAPTCHA challenge. Users are prompted to interact with this fake CAPTCHA, and in doing so, are inadvertently guided to input or execute commands within their command-line interface. This technique aims to bypass typical user caution by masquerading as a common security verification step.

Once the user is deceived into executing the malicious commands, the malware proceeds to deploy a backdoor onto the compromised system. This backdoor provides persistent access to the attacker, enabling further malicious activities such as data exfiltration, remote control, or the deployment of additional payloads. The specific functionalities of the backdoor were not detailed, but backdoors commonly allow for remote code execution, file manipulation, and system reconnaissance.

Microsoft's identification of TerminalFix highlights a shift in attack vectors. Previous iterations of similar malware, or other social engineering campaigns, have often targeted user interaction with the Windows Run dialog. The transition to exploiting Windows Terminal or PowerShell for command execution represents an adaptation that could potentially increase the success rate of such attacks, as users might be less suspicious of command-line prompts in certain contexts or might perceive them as part of a legitimate technical process.

Products in the Windows ecosystem are primarily affected, given the reliance on Windows Terminal and PowerShell. Users of Windows operating systems are advised to exercise extreme caution when encountering CAPTCHA challenges, especially those that prompt for command-line interaction or unusual steps. General mitigation strategies for this class of threat include user education on recognizing phishing and social engineering tactics, the implementation of endpoint detection and response (EDR) solutions, and maintaining up-to-date antivirus software.

To mitigate the risk posed by TerminalFix and similar threats, organizations and individual users should prioritize security awareness training. Emphasizing the importance of verifying the legitimacy of prompts, especially those requesting command-line input, is crucial. Additionally, employing robust security solutions that can detect and prevent the execution of malicious scripts, along with regularly patching operating systems and applications, forms a critical defense against evolving malware tactics.

This discovery underscores the continuous evolution of malware tactics, with attackers adapting their methods to exploit user trust and common interface elements. The move from targeting simpler dialog boxes to more technical command-line interfaces suggests a calculated effort to bypass established user security heuristics and potentially target users who may have a higher comfort level with command-line environments.

malwarebackdoorpowershellwindows terminalcaptcha
ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage. [...]

malware

Chrome Web Store extensions caught stealing crypto, browser data

Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, as well as inject ClickFix lures. [...]

malware

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 112

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Operation QUICSILVER: China-Nexus Actor Targets Myanmar Diplomats via VHD-Delivered Go Backdoor FTP Banners: The New Dead Drop Resolver Delivering Novel RATs The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic […]

ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

security

FulcrumSec claims Manchester Airports hack, theft of 86 GB of data

FulcrumSec claims it stole 86 GB of data from Manchester Airports Group. BleepingComputer validated one traveller's record, while samples revealed detailed customer, booking, and travel information beyond what MAG initially disclosed. [...]