'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks

2026-08-31T20:51:33Zc6a524e875bab23016329dc9547a88ebca6738f25eb2ae65cb2b91b821f00971
CVE-2026-73570AI-securityClickFixDark-CaracalICSLLM-poisoning vulnerabilitiesMicrosoft-365North-Korean-IT-workersOT-securityPowerShellRussian-threat-actorsZBT-routersZimbraadversary-in-the-middleagentic-AIbanking-trojanenterprise-securityindustrial-protocolsinfostealermalwarenation-statephishingreverse-tunnelingrouter-backdoorssession-theftthreat-intelligence

What happened

Dark Reading feed covering active enterprise attack campaigns, malware and phishing services, exploited vulnerabilities, nation-state operations, OT risks, and emerging security challenges involving agentic AI. Key items include a PowerShell-based ClickFix campaign using reverse tunnels, backdoored white-label ZBT routers, Russian phishing of EU officials via messaging apps, a Dark Caracal modular malware framework, Microsoft 365 session theft through AitM phishing, an exploited Zimbra takeover flaw (CVE-2026-73570), and vulnerabilities affecting AI model infrastructure and industrial systems.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
c6a524e875bab23016329dc9547a88ebca6738f25eb2ae65cb2b91b821f00971
Enrichment time
2026-08-31T20:51:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · 'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks · Baitaphish