New 'TerminalFix' Attack Tricks Users Into Hacking Their Own PCs via Fake CAPTCHAs
Microsoft researchers have uncovered a new attack technique called TerminalFix, a variation of the well-known ClickFix scam. Instead of tricking victims into using the Windows Run dialog, this method directs users to Windows Terminal or PowerShell — tools more commonly used by IT staff and technical users — to run a malicious command, often disguised as a fix for a fake Cloudflare CAPTCHA or verification prompt.
Because Terminal and PowerShell can handle more complex commands than the Run dialog, attackers can execute more sophisticated payloads once a victim is tricked into pasting and running the code. In this case, the attack deploys a reverse-tunnel backdoor, giving attackers remote access into the compromised system while evading many standard security controls.
This technique is particularly dangerous because it exploits user trust in familiar-looking web prompts and relies on social engineering rather than software vulnerabilities, making it harder to block with traditional patching alone. Businesses should treat any prompt asking them to copy and paste commands into Terminal or PowerShell — regardless of how legitimate it looks — as a major red flag.