Threat Intelligence

New 'TerminalFix' Attack Tricks Users Into Running Malicious PowerShell Commands

Dark Reading · 1 Sept 2026
Key Takeaway Train staff to never copy and paste commands into a terminal or PowerShell window based on an on-screen prompt, no matter how official it looks, and verify such requests through a separate channel first.

A new attack campaign dubbed 'TerminalFix' is targeting organisations by exploiting a familiar social engineering trick: convincing users to copy and run commands themselves. Known as a 'ClickFix-style' attack, it typically presents victims with a fake error message or verification prompt that instructs them to paste a command into their computer's terminal or PowerShell window to 'fix' an issue.

Once executed, the command kicks off a multistage attack chain. Rather than simply installing a single piece of malware, the campaign establishes reverse tunnels — hidden connections that let attackers reach back into the victim's network from the outside, bypassing many perimeter defences. This gives attackers a foothold for further compromise, potentially including data theft, lateral movement, or deployment of additional malicious tools.

What makes ClickFix-style attacks effective is that they rely on the user performing the action manually, which can help them slide past some automated security controls that watch for malicious files or links rather than user-typed commands. Because the technique specifically targets everyday behaviours like copying and pasting instructions, employee awareness is a critical line of defence alongside technical controls.

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.