Threat reportMalwareTL-2026-2203

Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel via ClickFix-Style DLL Sideloading

highACTIVE

Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel (TL-2026-2203), also tracked as TerminalFix, is a high-severity malware campaign, first published 2026-08-29. It has no confirmed attribution, affects Microsoft Windows (LockScreenContentServer.exe / DirectUI Engine, maps to 13 MITRE ATT&CK techniques (T1027.003, T1036.005, T1053.005), and is covered by 9 detection rules and 14 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
13MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
14Indicators of compromise

Key facts for TL-2026-2203

Threat ID
TL-2026-2203
Also known as
TerminalFix
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Detection rules
9
Indicators of compromise
14

Malware and tooling in Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel

Malware and tooling: dui70.dll (Windows DirectUI Engine, HijackLibs-documented sideload vector)

How Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel works

A ClickFix-style campaign uses counterfeit Cloudflare Turnstile CAPTCHA overlays on compromised websites to copy a malicious PowerShell command to the clipboard and lure victims into pasting it into Windows Terminal. The command stages a ZIP dropper from admetricslab[.]org, side-loads a malicious dui70.dll into a Microsoft-signed LockScreenContentServer.exe, and opens a Python-based (TerminalFix) reverse tunnel to gitnow[.]dev over TLS/WebSocket.

This campaign is a variant of the ClickFix social-engineering technique that Microsoft Defender Experts have tracked evolving throughout 2025-2026, moving execution away from the Windows+R Run dialog (which leaves RunMRU registry artifacts) and into Windows Terminal or PowerShell directly, where it blends into legitimate administrative workflows. In this instance, attacker-controlled or compromised websites display a counterfeit Cloudflare Turnstile CAPTCHA verification overlay. When the victim interacts with it, the page silently copies a malicious PowerShell one-liner to the clipboard and instructs the victim to paste and run it in Windows Terminal.

Once executed, the command retrieves a ZIP archive from the payload-staging domain admetricslab[.]org (observed download path: /get_verify?i=24807), saving it to %TEMP%\verify_pkg.zip before extracting its contents into a concealed subdirectory under C:\ProgramData\ and launching a batch file in the background. The archive contains a legitimate, Microsoft-signed LockScreenContentServer.exe (a Windows 8.1-era DirectUI Engine host binary normally located at C:\Windows\System32\) placed alongside a malicious dui70.dll. Because LockScreenContentServer.exe resolves dui70.dll via Windows' default DLL search order rather than an explicit, verified path, the attacker-supplied DLL is loaded in place of the real Windows DirectUI Engine library — a documented sideloading weakness affecting at least 19 built-in Windows executables (per the HijackLibs project). Part of the payload-retrieval chain also relies on steganography: attacker-controlled PNG images carry additional payload data hidden in their pixel channels.

Persistence is established two ways: a Registry Run key, and a scheduled task that relaunches LockScreenContentServer.exe roughly every 60 minutes, guaranteeing the sideloaded dui70.dll re-executes even after reboot or process termination. The malicious DLL deploys a bundled Python runtime and launches a custom implant, client.py, via pythonw.exe (the windowless Python interpreter, avoiding a visible console). client.py — the campaign's namesake "TerminalFix" component — opens a connection to the C2 domain gitnow[.]dev over TLS on port 443, then upgrades the connection to WebSocket to relay arbitrary TCP traffic. The implant implements SOCKS5-style proxy handling, letting the operator reach internal IPv4, IPv6, or hostname-based targets inside the victim's network — i.e., using the compromised host as a pivot/relay rather than only exfiltrating from it directly.

No CVE applies: this is a living-off-the-land / social-engineering chain (LOLBIN abuse of a legitimately signed Windows binary plus user-driven ClickFix execution), not a software vulnerability. The admetricslab[.]org staging domain was independently flagged on the UT1 malware blocklist (via IPFire DBL) on 2026-08-05 and is tracked as a payload-delivery indicator in ThreatFox, corroborating its use in ClickFix-class ZIP-dropper campaigns around the same window this activity was reported.

MITRE ATT&CK techniques used in TL-2026-2203

Defense Evasion

T1027.003 Steganography; T1036.005 Match Legitimate Resource Name or Location; T1564.001 Hidden Files and Directories; T1574.001 DLL

Persistence

T1053.005 Scheduled Task; T1547.001 Registry Run Keys / Startup Folder

Execution

T1059.001 PowerShell; T1059.006 Python; T1204.004 Malicious Copy and Paste

Command and Control

T1071.001 Web Protocols; T1090.001 Internal Proxy; T1572 Protocol Tunneling

defense-impairment

T1553.002 Code Signing

Affected products and versions in Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel

  • Microsoft — Windows (LockScreenContentServer.exe / DirectUI Engine dui70.dll DLL search-order abuse)
    Vulnerable versions: Windows 8.1 and later builds shipping dui70.dll and a LockScreenContentServer.exe-class host binary

Remediation for Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel

Patches

  • No vendor patch applies — this is abuse of a legitimately signed Windows binary (LOLBIN/DLL sideloading) combined with user-driven ClickFix execution, not a software vulnerability.

Immediate actions

  • Block network egress and DNS resolution to gitnow[.]dev and admetricslab[.]org at the perimeter/resolver layer.
  • Hunt for LockScreenContentServer.exe executing from any path other than C:\Windows\System32\ or C:\Windows\SystemApps\.
  • Search endpoints for dui70.dll present outside %SYSTEM32%/%SYSWOW64% and validate its digital signature against the legitimate Microsoft copy.
  • Review Registry Run keys and Task Scheduler for entries that relaunch LockScreenContentServer.exe on an hourly cadence.
  • Hunt for pythonw.exe processes with outbound TLS connections on port 443 followed by a WebSocket protocol upgrade.

Workarounds

  • Restrict interactive Windows Terminal/PowerShell execution for standard users via AppLocker or WDAC where operationally feasible.
  • Enforce PowerShell Constrained Language Mode and script-block logging to reduce the blast radius and improve visibility of pasted commands.

Longer-term hardening

  • Deploy Attack Surface Reduction / DLL allow-listing rules to block sideloading of built-in Windows libraries such as dui70.dll by non-standard host processes (per HijackLibs guidance and Sigma rules).
  • Add EDR behavioral detections for PowerShell or Windows Terminal (wt.exe) launched immediately following a clipboard-paste event, and for archive extraction into C:\ProgramData\ followed by execution of a signed binary from that path.
  • Run periodic user-awareness training on ClickFix / fake-CAPTCHA clipboard-paste lures, emphasizing that legitimate CAPTCHA/Turnstile verification never requires pasting or running a command in a terminal.

Timeline of Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel

  • admetricslab[.]org, the domain used to stage the ZIP archive dropper, was added to the UT1 malware blocklist (IPFire DBL) and separately tracked in ThreatFox as a payload_delivery indicator.
  • GBHackers on Security published the first public technical writeup of the fake-Cloudflare-CAPTCHA / TerminalFix campaign, detailing the ClickFix lure, DLL sideloading, persistence and C2 chain.
  • The sideloaded dui70.dll deploys a bundled Python runtime and launches the client.py (TerminalFix) implant via pythonw.exe, opening a reverse tunnel to gitnow[.]dev over TLS on port 443 upgraded to WebSocket, with SOCKS5-style relay to internal IPv4/IPv6/hostname targets.
  • Persistence is established via a Registry Run key and a scheduled task that relaunches LockScreenContentServer.exe roughly every 60 minutes.
  • Attacker-controlled PNG images carrying hidden payload data in their pixel channels are retrieved as part of the payload delivery chain.
  • The extracted, Microsoft-signed LockScreenContentServer.exe is executed outside its normal C:\Windows\System32\ location and side-loads the attacker-supplied dui70.dll placed alongside it in the application directory.
  • The pasted command downloads a ZIP archive from admetricslab[.]org (path /get_verify?i=24807) to %TEMP%\verify_pkg.zip and extracts it into a concealed subdirectory under C:\ProgramData\, then launches a batch file in the background.
  • Compromised websites serve a counterfeit Cloudflare Turnstile CAPTCHA overlay that copies a malicious PowerShell command to the victim's clipboard and instructs them to paste it into Windows Terminal.

Sources cited for Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel

Detection coverage for TL-2026-2203

As of 2026-08-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2203 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
14 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats