Threat reportMalwareTL-2026-2203
Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel via ClickFix-Style DLL Sideloading
Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel (TL-2026-2203), also tracked as TerminalFix, is a high-severity malware campaign, first published 2026-08-29. It has no confirmed attribution, affects Microsoft Windows (LockScreenContentServer.exe / DirectUI Engine, maps to 13 MITRE ATT&CK techniques (T1027.003, T1036.005, T1053.005), and is covered by 9 detection rules and 14 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 13MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 14Indicators of compromise
Key facts for TL-2026-2203
- Threat ID
- TL-2026-2203
- Also known as
- TerminalFix
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Detection rules
- 9
- Indicators of compromise
- 14
Malware and tooling in Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel
Malware and tooling: dui70.dll (Windows DirectUI Engine, HijackLibs-documented sideload vector)
How Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel works
A ClickFix-style campaign uses counterfeit Cloudflare Turnstile CAPTCHA overlays on compromised websites to copy a malicious PowerShell command to the clipboard and lure victims into pasting it into Windows Terminal. The command stages a ZIP dropper from admetricslab[.]org, side-loads a malicious dui70.dll into a Microsoft-signed LockScreenContentServer.exe, and opens a Python-based (TerminalFix) reverse tunnel to gitnow[.]dev over TLS/WebSocket.
This campaign is a variant of the ClickFix social-engineering technique that Microsoft Defender Experts have tracked evolving throughout 2025-2026, moving execution away from the Windows+R Run dialog (which leaves RunMRU registry artifacts) and into Windows Terminal or PowerShell directly, where it blends into legitimate administrative workflows. In this instance, attacker-controlled or compromised websites display a counterfeit Cloudflare Turnstile CAPTCHA verification overlay. When the victim interacts with it, the page silently copies a malicious PowerShell one-liner to the clipboard and instructs the victim to paste and run it in Windows Terminal.
Once executed, the command retrieves a ZIP archive from the payload-staging domain admetricslab[.]org (observed download path: /get_verify?i=24807), saving it to %TEMP%\verify_pkg.zip before extracting its contents into a concealed subdirectory under C:\ProgramData\ and launching a batch file in the background. The archive contains a legitimate, Microsoft-signed LockScreenContentServer.exe (a Windows 8.1-era DirectUI Engine host binary normally located at C:\Windows\System32\) placed alongside a malicious dui70.dll. Because LockScreenContentServer.exe resolves dui70.dll via Windows' default DLL search order rather than an explicit, verified path, the attacker-supplied DLL is loaded in place of the real Windows DirectUI Engine library — a documented sideloading weakness affecting at least 19 built-in Windows executables (per the HijackLibs project). Part of the payload-retrieval chain also relies on steganography: attacker-controlled PNG images carry additional payload data hidden in their pixel channels.
Persistence is established two ways: a Registry Run key, and a scheduled task that relaunches LockScreenContentServer.exe roughly every 60 minutes, guaranteeing the sideloaded dui70.dll re-executes even after reboot or process termination. The malicious DLL deploys a bundled Python runtime and launches a custom implant, client.py, via pythonw.exe (the windowless Python interpreter, avoiding a visible console). client.py — the campaign's namesake "TerminalFix" component — opens a connection to the C2 domain gitnow[.]dev over TLS on port 443, then upgrades the connection to WebSocket to relay arbitrary TCP traffic. The implant implements SOCKS5-style proxy handling, letting the operator reach internal IPv4, IPv6, or hostname-based targets inside the victim's network — i.e., using the compromised host as a pivot/relay rather than only exfiltrating from it directly.
No CVE applies: this is a living-off-the-land / social-engineering chain (LOLBIN abuse of a legitimately signed Windows binary plus user-driven ClickFix execution), not a software vulnerability. The admetricslab[.]org staging domain was independently flagged on the UT1 malware blocklist (via IPFire DBL) on 2026-08-05 and is tracked as a payload-delivery indicator in ThreatFox, corroborating its use in ClickFix-class ZIP-dropper campaigns around the same window this activity was reported.
MITRE ATT&CK techniques used in TL-2026-2203
Defense Evasion
T1027.003 Steganography; T1036.005 Match Legitimate Resource Name or Location; T1564.001 Hidden Files and Directories; T1574.001 DLL
Persistence
T1053.005 Scheduled Task; T1547.001 Registry Run Keys / Startup Folder
Execution
T1059.001 PowerShell; T1059.006 Python; T1204.004 Malicious Copy and Paste
Command and Control
T1071.001 Web Protocols; T1090.001 Internal Proxy; T1572 Protocol Tunneling
defense-impairment
Affected products and versions in Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel
- Microsoft — Windows (LockScreenContentServer.exe / DirectUI Engine dui70.dll DLL search-order abuse)
Vulnerable versions: Windows 8.1 and later builds shipping dui70.dll and a LockScreenContentServer.exe-class host binary
Remediation for Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel
Patches
- No vendor patch applies — this is abuse of a legitimately signed Windows binary (LOLBIN/DLL sideloading) combined with user-driven ClickFix execution, not a software vulnerability.
Immediate actions
- Block network egress and DNS resolution to gitnow[.]dev and admetricslab[.]org at the perimeter/resolver layer.
- Hunt for LockScreenContentServer.exe executing from any path other than C:\Windows\System32\ or C:\Windows\SystemApps\.
- Search endpoints for dui70.dll present outside %SYSTEM32%/%SYSWOW64% and validate its digital signature against the legitimate Microsoft copy.
- Review Registry Run keys and Task Scheduler for entries that relaunch LockScreenContentServer.exe on an hourly cadence.
- Hunt for pythonw.exe processes with outbound TLS connections on port 443 followed by a WebSocket protocol upgrade.
Workarounds
- Restrict interactive Windows Terminal/PowerShell execution for standard users via AppLocker or WDAC where operationally feasible.
- Enforce PowerShell Constrained Language Mode and script-block logging to reduce the blast radius and improve visibility of pasted commands.
Longer-term hardening
- Deploy Attack Surface Reduction / DLL allow-listing rules to block sideloading of built-in Windows libraries such as dui70.dll by non-standard host processes (per HijackLibs guidance and Sigma rules).
- Add EDR behavioral detections for PowerShell or Windows Terminal (wt.exe) launched immediately following a clipboard-paste event, and for archive extraction into C:\ProgramData\ followed by execution of a signed binary from that path.
- Run periodic user-awareness training on ClickFix / fake-CAPTCHA clipboard-paste lures, emphasizing that legitimate CAPTCHA/Turnstile verification never requires pasting or running a command in a terminal.
Timeline of Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel
- admetricslab[.]org, the domain used to stage the ZIP archive dropper, was added to the UT1 malware blocklist (IPFire DBL) and separately tracked in ThreatFox as a payload_delivery indicator.
- GBHackers on Security published the first public technical writeup of the fake-Cloudflare-CAPTCHA / TerminalFix campaign, detailing the ClickFix lure, DLL sideloading, persistence and C2 chain.
- The sideloaded dui70.dll deploys a bundled Python runtime and launches the client.py (TerminalFix) implant via pythonw.exe, opening a reverse tunnel to gitnow[.]dev over TLS on port 443 upgraded to WebSocket, with SOCKS5-style relay to internal IPv4/IPv6/hostname targets.
- Persistence is established via a Registry Run key and a scheduled task that relaunches LockScreenContentServer.exe roughly every 60 minutes.
- Attacker-controlled PNG images carrying hidden payload data in their pixel channels are retrieved as part of the payload delivery chain.
- The extracted, Microsoft-signed LockScreenContentServer.exe is executed outside its normal C:\Windows\System32\ location and side-loads the attacker-supplied dui70.dll placed alongside it in the application directory.
- The pasted command downloads a ZIP archive from admetricslab[.]org (path /get_verify?i=24807) to %TEMP%\verify_pkg.zip and extracts it into a concealed subdirectory under C:\ProgramData\, then launches a batch file in the background.
- Compromised websites serve a counterfeit Cloudflare Turnstile CAPTCHA overlay that copies a malicious PowerShell command to the victim's clipboard and instructs them to paste it into Windows Terminal.
Sources cited for Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel
- Hackers Use Fake Cloudflare CAPTCHA to Deploy TerminalFix Reverse Tunnel
- dui70.dll on HijackLibs
- Think before you Click(Fix): Analyzing the ClickFix social engineering technique
- User Execution: Malicious Copy and Paste, Sub-technique T1204.004 - Enterprise | MITRE ATT&CK
- ThreatFox IOC Database - admetricslab.org
- IPFire DBL - Malware - Domain admetricslab.org
- LockScreenContentServer.exe hash/signature record - herdProtect
- ClickFix Evolves Using Decade-Old Open-Source Python SOCKS5 Proxy
Detection coverage for TL-2026-2203
As of 2026-08-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2203 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.