TerminalFix campaign deploys a reverse tunnel through multistage intrusion

2026-09-01T14:52:11Z19c0f306c30621f2bdcbaf24046b051c7be2831da16d2debc828ca37b438a2c5
ClickFixDLL sideloadingMicrosoft Threat IntelligenceTerminalFixdefense evasionfake CAPTCHAmultistage intrusionremote accessreverse tunnelsocial engineering

What happened

Microsoft Threat Intelligence reports on the TerminalFix ClickFix campaign, which uses fake CAPTCHA prompts to trick users into executing commands, DLL sideloading, multistage payload delivery, and a reverse tunnel for persistent remote access. The campaign reflects active social engineering and defense-evasion techniques and includes detection and threat-hunting guidance.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
19c0f306c30621f2bdcbaf24046b051c7be2831da16d2debc828ca37b438a2c5
Enrichment time
2026-09-01T14:52:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.