TerminalFix: ClickFix-Style Fake Cloudflare CAPTCHA Delivers DLL Sideloading and Python Reverse-Tunnel Backdoor
TerminalFix: ClickFix-Style Fake Cloudflare CAPTCHA Delivers (TL-2026-2237) is a high-severity malware campaign, first published 2026-08-30. It has no confirmed attribution, affects Microsoft Windows workstations and domain-joined endpoints (Windows, maps to 15 MITRE ATT&CK techniques (T1018, T1027.003, T1036.005), and is covered by 9 detection rules and 25 indicators of compromise.
Key facts for TL-2026-2237
- Threat ID
- TL-2026-2237
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-08-30
- Last reviewed
- 2026-08-30
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Detection rules
- 9
- Indicators of compromise
- 25
Malware and tooling in TerminalFix: ClickFix-Style Fake Cloudflare CAPTCHA Delivers
Malware and tooling: TerminalFix, Trojan:Python/Indigo.SA, Trojan:Win64/DLLHijack.DAB!MTB, Custom Python WebSocket reverse-tunnel implant
TerminalFix, a ClickFix-variant social-engineering campaign disclosed by Microsoft on 2026-08-28, uses fake Cloudflare Turnstile CAPTCHA overlays on compromised websites to trick victims into pasting malicious PowerShell into Windows Terminal. The resulting multi-stage intrusion sideloads a rogue dui70.dll via the signed LockScreenContentServer.exe, pulls next-stage payloads hidden in PNG steganography, performs Active Directory reconnaissance, and deploys a custom Python reverse-tunnel implant (client.py) that proxies arbitrary TCP traffic to gitnow[.]dev over an encrypted WebSocket.
How TerminalFix: ClickFix-Style Fake Cloudflare CAPTCHA Delivers works
TerminalFix is a newly documented ClickFix variant that Microsoft Threat Intelligence (researchers Sagar Patil, Suriyaraj Natarajan, and Parasharan Raghavan) disclosed on 2026-08-28. Unlike earlier ClickFix campaigns that lure victims to the Windows Run dialog to deploy a single infostealer, TerminalFix directs victims to Windows Terminal or PowerShell — improving reliability for longer, multi-line scripts — and delivers a far more elaborate, multi-stage intrusion chain.
Victims land on compromised websites displaying a fake Cloudflare Turnstile verification overlay. The "verification" instructs the user to paste and run a PowerShell command, which downloads a ZIP archive (SHA-256 18c2090e8a0ae0568af9b87e59eaf8270f23d2909600ed9db91a9444fd8b278f) using a custom User-Agent header, extracts it to a hidden staging folder (C:\ProgramData\f47f2a8c21c9df4e, hidden via attrib +h +s), and launches a batch file (1.bat) that silently starts the legitimate signed binary LockScreenContentServer.exe while the terminal prints fake Cloudflare verification text to keep the user occupied.
LockScreenContentServer.exe has a static import dependency on the real Windows DirectUI Engine DLL, dui70.dll. Because the Windows loader searches the application directory before System32, dropping a malicious dui70.dll (observed in at least nine SHA-256 variants) alongside the legitimate EXE causes the trusted binary to load and execute attacker code — classic DLL side-loading (T1574.002). The sideloaded DLL then retrieves further payloads hidden inside PNG images via a custom PowerShell function (Extract-RawFileFromImage) that reads the RGBA pixel channels: the first 8 bytes encode a 64-bit payload length, the remainder is the embedded file. Three images are fetched via POST requests from bestsocialmedianewspapper[.]com (primary) or offlineupdater[.]com (failover), with the DLL payload split across two images to hinder static analysis; source images are deleted after extraction to reduce forensic residue.
Persistence is established two ways: a Registry Run key (HKCU\Software\Microsoft\Windows\CurrentVersion\Run\LockScreenContentServer_MuODG5yBM) and a scheduled task of the same name that re-executes LockScreenContentServer.exe every 60 minutes.
The implant then performs extensive Active Directory reconnaissance: domain trust discovery (nltest /domain_trusts, nltest /dclist:), domain admin group enumeration (net group "domain admins" /domain), AD user/computer searches via ADSI with description-field harvesting, systeminfo collection with multilingual (English/Spanish/German) findstr filters, and ping sweeps of discovered infrastructure roles (domain controllers, database servers, backup systems, gateways, mail systems). A persistent PowerShell file-watch loop also monitors a text file for attacker commands, executes them via Invoke-Expression, and writes results to an output file — a rudimentary asynchronous, filesystem-based C2 channel that runs in parallel with the primary implant.
The final stage deploys client.py (SHA-256 b8d107800403b9197e5b7609ceacd8e4cac1b0f9a1d156e6dacd6c3f7794b36a), a custom reverse-tunnel implant run under an unmodified, official python.org Python 3.14.5 distribution via pythonw.exe (no visible window) to avoid raising suspicion. The implant connects outbound over TLS on port 443 to gitnow[.]dev, upgrades to a WebSocket at the /tunnel endpoint, disables certificate verification (CERT_NONE), and rotates among four realistic browser User-Agent strings. A 7-byte custom binary header (message type + stream ID + length) multiplexes multiple tunneled streams, with SOCKS5-style address parsing supporting IPv4, IPv6, and hostname targets — giving the operator arbitrary TCP proxy access to any host reachable from the compromised endpoint. Message types cover implant identification, connection setup, data relay, keepalive, and remote termination (MSG_SHUTDOWN, which calls os._exit() to bypass normal Python cleanup).
Microsoft did not attribute the campaign to a named actor or group and did not specify targeted sectors or regions beyond "organizations across multiple industries." Microsoft assesses that the reverse-tunnel access this campaign establishes could subsequently be leveraged for privilege escalation, security-control tampering, data exfiltration, and ransomware deployment across enterprise networks, though no such follow-on activity has been confirmed in the public reporting. Microsoft Defender Antivirus detects components under Trojan:Win32/ClickFix.*, Trojan:Win32/TermFix.*, Trojan:Win32/Posilod.*, Trojan:Win64/DLLHijack.DAB!MTB, and Trojan:Python/Indigo.SA, and Microsoft published Defender XDR/Sentinel KQL hunting queries for the ClickFix PowerShell launch, the DLL sideload, the client.py execution, and network connections to the campaign's domains.
MITRE ATT&CK techniques used in TL-2026-2237
Discovery
T1018 Remote System Discovery; T1069.002 Domain Groups; T1082 System Information Discovery; T1087.002 Domain Account; T1482 Domain Trust Discovery
Defense Evasion
T1027.003 Steganography; T1036.005 Match Legitimate Resource Name or Location; T1564.001 Hidden Files and Directories; T1574.001 DLL
Persistence
T1053.005 Scheduled Task; T1547.001 Registry Run Keys / Startup Folder
Execution
T1059.001 PowerShell; T1204.002 Malicious File
Command and Control
Affected products and versions in TerminalFix: ClickFix-Style Fake Cloudflare CAPTCHA Delivers
- Microsoft — Windows workstations and domain-joined endpoints (Windows Terminal / PowerShell environments)
Vulnerable versions: Windows 10; Windows 11; Windows Server (domain-joined)
Remediation for TerminalFix: ClickFix-Style Fake Cloudflare CAPTCHA Delivers
Patches
- Not applicable — TerminalFix abuses a legitimate signed Microsoft binary (DLL side-loading) rather than exploiting a specific CVE
Immediate actions
- Block/monitor network egress and DNS resolution to gitnow.dev, bestsocialmedianewspapper.com, offlineupdater.com, and linked-log.com
- Hunt for LockScreenContentServer.exe running outside its legitimate installation path with a co-located dui70.dll, and for the hidden C:\ProgramData\f47f2a8c21c9df4e directory
- Remove the Run key and scheduled task named LockScreenContentServer_MuODG5yBM and terminate any resulting pythonw.exe/python.exe process running client.py
Workarounds
- Restrict or alert on pythonw.exe/python.exe execution for standard users in environments where Python is not a business requirement
- Deploy Microsoft's published Defender XDR/Sentinel KQL hunting queries for the ClickFix PowerShell launch, dui70.dll sideload, client.py execution, and gitnow.dev connections
Longer-term hardening
- Restrict PowerShell and Windows Terminal execution for standard users via AppLocker, Windows Defender Application Control, or Group Policy
- Enable PowerShell Script Block Logging and forward to SIEM/XDR for ClickFix-style paste-and-run command detection
- Deploy user-awareness training explicitly stating that legitimate CAPTCHA/verification pages never ask users to paste commands into a terminal or Run dialog
Timeline of TerminalFix: ClickFix-Style Fake Cloudflare CAPTCHA Delivers
- Python reverse-tunnel implant client.py (SHA-256 b8d107800403b9197e5b7609ceacd8e4cac1b0f9a1d156e6dacd6c3f7794b36a) documented connecting to gitnow.dev over a TLS-wrapped WebSocket on port 443.
- Active Directory reconnaissance activity (domain trust discovery, domain admin enumeration, AD user/computer searches, ping sweeps) documented.
- Dual persistence via a Registry Run key and a 60-minute scheduled task, both named LockScreenContentServer_MuODG5yBM, documented.
- Steganographic delivery of split payloads inside PNG images from bestsocialmedianewspapper.com (primary) and offlineupdater.com (failover) documented.
- dui70.dll sideloading via the signed LockScreenContentServer.exe documented as the primary defense-evasion/execution technique (T1574.002).
- Malicious ZIP archive (SHA-256 18c2090e8a0ae0568af9b87e59eaf8270f23d2909600ed9db91a9444fd8b278f) containing LockScreenContentServer.exe and dui70.dll identified as the stage-2 dropper, extracted to a hidden C:\ProgramData staging folder.
- Fake Cloudflare Turnstile CAPTCHA overlays on compromised websites documented luring victims into pasting malicious PowerShell into Windows Terminal or PowerShell.
- Microsoft Threat Intelligence (Sagar Patil, Suriyaraj Natarajan, Parasharan Raghavan) publishes the TerminalFix campaign disclosure detailing the full multistage intrusion chain.
- GBHackers and OffSeq Threat Radar publish independent coverage corroborating Microsoft's IOCs and attack chain.
- The Hacker News publishes coverage citing Microsoft's findings; ingested into the TL-Intel hunt backlog as TL-2026-2237.
Sources cited for TerminalFix: ClickFix-Style Fake Cloudflare CAPTCHA Delivers
- TerminalFix campaign deploys a reverse tunnel through multistage intrusion
- TerminalFix Uses Fake Cloudflare CAPTCHA to Deliver DLL Sideloading Malware
- Hackers Use Fake Cloudflare CAPTCHA to Deploy TerminalFix Reverse Tunnel
- TerminalFix campaign deploys a reverse tunnel through multistage intrusion
- TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
- TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
- TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
More in malware
- MacSync (Mac.c) macOS Info-Stealer Abuses Public iCloud Calendars as C2 Dead-Drop in Fake "Toria" Crypto Wallet Campaign
- TWEAKOS Stealer: Discord Token Theft and Telegram Account-Takeover Marketplace
- Infostealer Market Resilience: Law Enforcement Takedowns Displace, Not Eliminate, RedLine/META/LummaC2/Rhadamanthys Activity
- ClickFix Campaign Abuses Compromised Ukrainian Websites to Deploy Psychedelic Stealer
- CARBONATO Botnet Exploits Exposed Docker Daemons to Deploy AI Agent Framework, Prioritizes AI API Key Theft
Detection coverage for TL-2026-2237
As of 2026-08-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2237 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.