Threat Intelligence

New 'TerminalFix' Attack Tricks Users Into Hacking Their Own PCs via Fake CAPTCHAs

The Hacker News · 30 Aug 2026
Key Takeaway Train staff to never copy-paste and run commands in Terminal or PowerShell based on website prompts, even ones that look like official CAPTCHA or verification checks.

Microsoft researchers have uncovered a new attack technique called TerminalFix, a variation of the well-known ClickFix scam. Instead of tricking victims into using the Windows Run dialog, this method directs users to Windows Terminal or PowerShell — tools more commonly used by IT staff and technical users — to run a malicious command, often disguised as a fix for a fake Cloudflare CAPTCHA or verification prompt.

Because Terminal and PowerShell can handle more complex commands than the Run dialog, attackers can execute more sophisticated payloads once a victim is tricked into pasting and running the code. In this case, the attack deploys a reverse-tunnel backdoor, giving attackers remote access into the compromised system while evading many standard security controls.

This technique is particularly dangerous because it exploits user trust in familiar-looking web prompts and relies on social engineering rather than software vulnerabilities, making it harder to block with traditional patching alone. Businesses should treat any prompt asking them to copy and paste commands into Terminal or PowerShell — regardless of how legitimate it looks — as a major red flag.

ClickFix social engineering PowerShell security backdoor malware Windows Terminal

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.