# Fake Cloudflare CAPTCHA Delivers TerminalFix Reverse Tunnel via ClickFix-Style DLL Sideloading

> A ClickFix-style campaign uses counterfeit Cloudflare Turnstile CAPTCHA overlays on compromised websites to copy a malicious PowerShell command to the clipboard and lure victims into pasting it into Windows Terminal. The command stages a ZIP dropper from admetricslab[.]org, side-loads a malicious dui70.dll into a Microsoft-signed LockScreenContentServer.exe, and opens a Python-based (TerminalFix) reverse tunnel to gitnow[.]dev over TLS/WebSocket.

- **Published:** 2026-08-29T00:00:00Z
- **Last reviewed:** 2026-08-29T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2203
- **ID:** TL-2026-2203
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 14 (full data via the Threadlinqs MCP server — Purple tier)

## Description

This campaign is a variant of the ClickFix social-engineering technique that Microsoft Defender Experts have tracked evolving throughout 2025-2026, moving execution away from the Windows+R Run dialog (which leaves RunMRU registry artifacts) and into Windows Terminal or PowerShell directly, where it blends into legitimate administrative workflows. In this instance, attacker-controlled or compromised websites display a counterfeit Cloudflare Turnstile CAPTCHA verification overlay. When the victim interacts with it, the page silently copies a malicious PowerShell one-liner to the clipboard and instructs the victim to paste and run it in Windows Terminal.

Once executed, the command retrieves a ZIP archive from the payload-staging domain admetricslab[.]org (observed download path: /get_verify?i=24807), saving it to %TEMP%\verify_pkg.zip before extracting its contents into a concealed subdirectory under C:\ProgramData\ and launching a batch file in the background. The archive contains a legitimate, Microsoft-signed LockScreenContentServer.exe (a Windows 8.1-era DirectUI Engine host binary normally located at C:\Windows\System32\) placed alongside a malicious dui70.dll. Because LockScreenContentServer.exe resolves dui70.dll via Windows' default DLL search order rather than an explicit, verified path, the attacker-supplied DLL is loaded in place of the real Windows DirectUI Engine library — a documented sideloading weakness affecting at least 19 built-in Windows executables (per the HijackLibs project). Part of the payload-retrieval chain also relies on steganography: attacker-controlled PNG images carry additional payload data hidden in their pixel channels.

Persistence is established two ways: a Registry Run key, and a scheduled task that relaunches LockScreenContentServer.exe roughly every 60 minutes, guaranteeing the sideloaded dui70.dll re-executes even after reboot or process termination. The malicious DLL deploys a bundled Python runtime and launches a custom implant, client.py, via pythonw.exe (the windowless Python interpreter, avoiding a visible console). client.py — the campaign's namesake "TerminalFix" component — opens a connection to the C2 domain gitnow[.]dev over TLS on port 443, then upgrades the connection to WebSocket to relay arbitrary TCP traffic. The implant implements SOCKS5-style proxy handling, letting the operator reach internal IPv4, IPv6, or hostname-based targets inside the victim's network — i.e., using the compromised host as a pivot/relay rather than only exfiltrating from it directly.

No CVE applies: this is a living-off-the-land / social-engineering chain (LOLBIN abuse of a legitimately signed Windows binary plus user-driven ClickFix execution), not a software vulnerability. The admetricslab[.]org staging domain was independently flagged on the UT1 malware blocklist (via IPFire DBL) on 2026-08-05 and is tracked as a payload-delivery indicator in ThreatFox, corroborating its use in ClickFix-class ZIP-dropper campaigns around the same window this activity was reported.

## MITRE ATT&CK

- T1204.004 Malicious Copy and Paste
- T1059.001 PowerShell
- T1059.006 Python
- T1547.001 Registry Run Keys / Startup Folder
- T1053.005 Scheduled Task
- T1574.001 DLL
- T1036.005 Match Legitimate Resource Name or Location
- T1564.001 Hidden Files and Directories
- T1553.002 Code Signing
- T1027.003 Steganography
- T1572 Protocol Tunneling
- T1071.001 Web Protocols
- T1090.001 Internal Proxy

## Sources

- [Hackers Use Fake Cloudflare CAPTCHA to Deploy TerminalFix Reverse Tunnel](https://gbhackers.com/hackers-use-fake-cloudflare-captcha/)
- [dui70.dll on HijackLibs](https://hijacklibs.net/entries/microsoft/built-in/dui70.html)
- [Think before you Click(Fix): Analyzing the ClickFix social engineering technique](https://www.microsoft.com/en-us/security/blog/2025/08/21/think-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique/)
- [User Execution: Malicious Copy and Paste, Sub-technique T1204.004 - Enterprise | MITRE ATT&CK](https://attack.mitre.org/techniques/T1204/004/)
- [ThreatFox IOC Database - admetricslab.org](https://threatfox.abuse.ch/ioc/1868831/)
- [IPFire DBL - Malware - Domain admetricslab.org](https://www.ipfire.org/dbl/lists/malware/domains/admetricslab.org)
- [LockScreenContentServer.exe hash/signature record - herdProtect](http://www.herdprotect.com/lockscreencontentserver.exe-b88f5b459f912ce5efd0ce517ef9bd22fde170e4.aspx)
- [ClickFix Evolves Using Decade-Old Open-Source Python SOCKS5 Proxy](https://gbhackers.com/open-source-python-socks5-proxy/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2203
