Back Issues/Search Home → Calendar → Archive → Current Issue → Popular →

All issuesVolume 341, Issue 4IT Vendor NewsMicrosoft

TerminalFix Campaign Deploys a Reverse Tunnel Through Multistage Intrusion

Microsoft, Saturday, August 29th, 2026

Microsoft Threat Intelligence analyzes a ClickFix campaign using fake CAPTCHAs, DLL sideloading and a reverse tunnel.

Microsoft Threat Intelligence has published analysis of TerminalFix, a ClickFix campaign that chains several techniques into a multistage intrusion. The initial access uses fake CAPTCHA prompts to persuade the victim to execute attacker-supplied commands themselves, bypassing controls that would block a downloaded payload.

Subsequent stages employ DLL sideloading to run malicious code under the cover of a legitimate signed binary.

The campaign establishes a reverse tunnel for persistent access back into the environment. Microsoft provides detections and hunting guidance so defenders can search for the activity in their own telemetry.

more →  ·  More from Microsoft →