Yaamlabs
Threat intel

TerminalFix: a ClickFix lookalike that opens a tunnel

TerminalFix uses the familiar fake CAPTCHA but sends victims to Windows Terminal and installs a reverse tunnel into the network. How to spot and block it.

By Yaali. September 28, 2026, 6 min read, Threat intel, Windows.

Cover illustration of a browser verification checkbox wired to a terminal window and a cluster of servers, with the Yaamlabs logo and the text: TerminalFix looks like ClickFix, opens a network tunnel, gitnow.dev:443 tunnel endpoint

Microsoft Threat Intelligence has published details of TerminalFix, a campaign that plants fake Cloudflare verification pages on compromised websites and talks visitors into pasting a PowerShell command themselves. Microsoft reported it on August 28, 2026, after seeing it hit organizations in multiple industries, and Malwarebytes followed up in September. To the person at the keyboard it looks like every other ClickFix page seen this year.

What happens next is different. Typical ClickFix pages drop an infostealer that grabs browser passwords and leaves. TerminalFix maps the Active Directory domain and installs a Python reverse tunnel that lets the operator reach other machines on the internal network through the victim's PC. It also swaps the Run dialog for Windows Terminal, which means a detection or forensic check built around the classic ClickFix trail can miss it completely.

Comparison of typical ClickFix and TerminalFix after the same fake verification lure: ClickFix uses the Run dialog, leaves a RunMRU entry and drops an infostealer; TerminalFix uses Windows Terminal or PowerShell, leaves no RunMRU entry, sideloads a DLL and rebuilds code from three PNGs, then runs AD reconnaissance and a reverse tunnel to gitnow.dev on port 443

How it works

ClickFix needs no software flaw. A compromised or malicious page shows a fake CAPTCHA or error message. When the visitor clicks the checkbox, JavaScript on the page writes a command to the clipboard, and the page then shows instructions: open a window, paste, press Enter. Because the user types and runs the command, there is no downloaded file for the browser to warn about and no attachment for the mail filter to scan. The command runs with the user's own rights.

The classic version asks for Windows+R, the Run dialog. Every command entered there is saved in the registry under HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU, which is why RunMRU became the first place incident responders look after a ClickFix report. Detection rules and awareness training built around that path watch for Win+R specifically.

TerminalFix tells the victim to open Windows Terminal or PowerShell instead. A terminal session looks like normal admin work, handles long multi-line scripts that the Run dialog copes with badly, and writes nothing to RunMRU. The pasted command clears the screen and prints a fake "Starting Cloudflare verification" message in cyan while it downloads a ZIP archive, unpacks it to C:\ProgramData\f47f2a8c21c9df4e and runs 1.bat.

From there the chain avoids anything that looks obviously malicious:

  • DLL sideloading: the archive holds LockScreenContentServer.exe, a genuine signed Windows binary, and a malicious dui70.dll. Windows looks for DLLs in the program's own folder before System32, so the signed program loads the attacker's DLL. The DLL decodes its next stage in memory.
  • Steganography: PowerShell downloads three ordinary looking PNG files from bestsocialmedianewspapper[.]com and offlineupdater[.]com. A function called Extract-RawFileFromImage reads the RGBA values of each pixel, takes the first 8 bytes as the payload length, and rebuilds an executable and two DLL fragments. The images are then deleted.
  • Persistence and hiding: a randomly named value under the user's Run registry key, a scheduled task that restarts LockScreenContentServer.exe every 60 minutes, and attrib +h +s on the staging folder.

What attackers are doing

The payload is built for network access. The malware runs nltest /domain_trusts and nltest /dclist:, net group "domain admins" /domain, harvests Active Directory user descriptions, and uses an ADSI query to list Windows servers and ping sweep them. BleepingComputer's summary of the Microsoft report says it probes for domain controllers, databases, backup servers, gateways and mail servers.

It then installs an embedded Python 3.14.5 runtime and runs client.py with pythonw.exe. The implant connects over TLS to gitnow[.]dev on port 443, upgrades to a WebSocket at /tunnel, and relays arbitrary TCP connections SOCKS5 style, with several streams multiplexed over one socket, browser User-Agent strings that rotate, and TLS certificate checks disabled. The effect is a remote access doorway that looks like web traffic. Microsoft says it did not observe hands-on-keyboard activity through the tunnel during its investigation, and no source gives a victim count, so the scale is unknown.

Other ClickFix activity this month shows how busy the lure itself is. Netskope Threat Labs found more than 5,400 compromised websites, belonging to over 2,200 organizations and mostly small WordPress and PrestaShop sites, serving fake CAPTCHA pages with payloads stored on the BNB Smart Chain. Arctic Wolf reported hacked Ukrainian business sites pushing a new infostealer called Psychedelic through a Run dialog command that calls msiexec.exe; it takes browser passwords, account tokens and cryptocurrency wallets. Both use the Run dialog and steal data, which is the profile most ClickFix detections were written for.

What to do

Priority actions against TerminalFix: restrict PowerShell and Windows Terminal for standard users, keep the multi-line paste warning and ASR rules on, hunt for the specific indicators, and treat a hit as a network intrusion

There is no vulnerability and nothing to patch, so every fix here is configuration, detection or training.

Close more than the Run dialog. Group Policy "Remove Run menu from Start Menu" (User Configuration, Administrative Templates, Start Menu and Taskbar) disables Win+R, and it still helps against the classic campaigns. It does nothing against TerminalFix. Microsoft recommends AppLocker or App Control for Business rules that stop standard users from running PowerShell, Constrained Language Mode where they must have it, and an execution policy of AllSigned or RemoteSigned. Staff who never use a shell can have Windows Terminal blocked too.

Keep the paste warning on. Windows Terminal warns before pasting text with more than one line through the multiLinePasteWarning setting. It is on by default, so check your managed builds have not switched it off. It only fires on multi-line pastes, so treat it as one layer.

Turn on the Defender attack surface reduction (ASR) rules Microsoft lists: block execution of potentially obfuscated scripts, block executables that do not meet a prevalence, age or trusted list criterion, and block JavaScript or VBScript from launching downloaded executable content. Defender detects this campaign as Trojan:Win32/TermFix, Trojan:Win32/ClickFix, Trojan:Win64/DLLHijack.DAB!MTB and Trojan:Python/Indigo.SA. Block the three domains above at DNS or the web proxy.

Hunt beyond RunMRU. Check it still, but for TerminalFix look at:

  • PowerShell script block logging, event ID 4104 in Microsoft-Windows-PowerShell/Operational. Enable it by policy if it is off.
  • The PSReadLine history file, %APPDATA%\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt, which keeps commands pasted into an interactive PowerShell session.
  • Process creation where WindowsTerminal.exe or powershell.exe starts LockScreenContentServer.exe, or where that binary runs from anywhere other than C:\Windows\System32.
  • pythonw.exe running from ProgramData, and outbound connections to gitnow[.]dev.

Microsoft's advanced hunting query for the sideload is short:

DeviceImageLoadEvents
| where InitiatingProcessFileName =~ "LockScreenContentServer.exe"
| where FileName =~ "dui70.dll"

When a user reports "a CAPTCHA asked me to paste something", Windows clipboard history (Win+V, if enabled) may still show the exact command.

Treat a hit as a network intrusion. Isolate the machine and remove the scheduled task, Run key and hidden ProgramData folder. Because the tunnel exists to reach other systems, review connections from that host to domain controllers and servers, and rotate credentials the user or machine could reach, including domain admin accounts if reconnaissance ran.

Train the mechanism. Show staff how the trick works: the page fills the clipboard, and they are asked to paste it into a window that runs commands. No real website asks for that, whether the window is Run, a terminal, PowerShell or the next one attackers pick.

We test these controls in safeguarding and hardening reviews and hunt for ClickFix-style execution in security operations. To check whether your endpoints would stop TerminalFix, open the chat and Yaali, our AI agent, will pass your question to an engineer.


Sources: Microsoft Security Blog, Malwarebytes, BleepingComputer, Hackread, RH-ISAC, BleepingComputer on the 5,400 sites, Fox News, Arctic Wolf, Security Affairs, Windows Terminal paste warning.

Read next

Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.