Fake Cloudflare CAPTCHA Attack Deploys Reverse Tunnel

TerminalFix campaign uses fake Cloudflare CAPTCHA to breach networks via user-pasted commands

Fake Cloudflare CAPTCHA Reverse Tunnel Attack: What Happened?

A new cyber campaign is targeting corporate networks using a fake Cloudflare CAPTCHA as a lure, according to a report from Microsoft. This attack, dubbed TerminalFix, tricks users into running malicious commands, ultimately deploying a custom reverse tunnel that gives attackers access to internal systems. The campaign represents a sophisticated blend of social engineering and technical subterfuge, posing a real risk to organisations across multiple industries.

Attack Timeline and Infection Chain

TerminalFix was first observed in early 2024, with Microsoft identifying an uptick in incidents affecting small and medium-sized businesses. Attackers compromise legitimate websites and replace routine CAPTCHA checks with a lookalike page branded as Cloudflare. Unsuspecting users, believing they are completing a standard verification, are instead instructed to copy and paste a command into Windows Terminal or PowerShell.

  • Initial Access: Website visitors are redirected to the fake Cloudflare CAPTCHA page.
  • Social Engineering: The page displays instructions, convincing users to paste a provided command into a Windows command-line tool.
  • Payload Delivery: The command downloads a ZIP archive containing the malicious payload.
  • Execution: The archive is unpacked under ProgramData, and a background batch file is launched.
  • Persistence and Reconnaissance: The malware hides its code, maps the organisational environment, and sets up persistence mechanisms.
  • Reverse Tunnel Deployment: A custom reverse tunnel is established, routing traffic from the victim’s system to the attacker’s infrastructure.

This multistage chain is notable for its reliance on the victim’s active participation, demonstrating a blend of technical exploitation and targeted social manipulation.

Technical Analysis of TerminalFix

TerminalFix is a more capable evolution of the earlier ClickFix campaign. After the initial command is executed, the attack chain unfolds in several stages:

  • DLL Sideloading: The malware sideloads malicious DLLs to avoid detection and maintain persistence.
  • Steganography: Malicious code is hidden within images, helping the attack evade basic signature-based security tools.
  • Environment Mapping: The malware actively scans the local network, identifying valuable systems and resources.
  • Reverse Tunnel Creation: A custom-built reverse tunnel connects the compromised endpoint to the attacker, enabling further exploitation and data exfiltration.

Microsoft analysts have confirmed that TerminalFix’s reverse tunnel is not based on widely available open-source tools but instead uses a bespoke protocol, making detection and mitigation more difficult.

The attack does not exploit a specific software vulnerability, but rather abuses user trust and leverages legitimate administrative tools found on Windows systems. The campaign targets a broad range of industries, with successful infections reported in sectors such as professional services, retail and manufacturing.

Who Is Affected?

TerminalFix targets Windows environments where employees have access to command-line tools. Because the attack begins with a social engineering lure, any user with sufficient privileges to run commands in Windows Terminal or PowerShell is at risk. Microsoft’s telemetry indicates that incidents have been detected across Europe and North America, with particular impact on small and medium-sized businesses lacking advanced endpoint controls.

There are no specific product or version requirements, though the attack chain has been observed on Windows 10 and Windows 11 systems as well as Windows Server environments.

Current Exploitation Status

As of June 2024, TerminalFix remains an active threat. Microsoft and other security vendors are monitoring ongoing campaigns, with evidence of continued compromise attempts. The reverse tunnel component allows attackers to maintain persistent access, increasing the risk of lateral movement and further exploitation within affected networks.

Security researchers have noted that the attack’s reliance on user action gives defenders an opportunity to intervene through user awareness and endpoint monitoring, but the ongoing nature of the campaign means vigilance is required.

Why This Matters for Organisations

This campaign demonstrates how attackers can bypass traditional defences by targeting the human element, rather than relying solely on technical exploits. The use of a trusted brand (Cloudflare) and realistic CAPTCHA imitation increases the likelihood of user compliance. The custom reverse tunnel enables attackers to exfiltrate data or deploy additional payloads, posing a significant risk to business operations and sensitive information.

What Organisations Should Do Now

  • Warn employees about this specific attack, especially the risks of running unsolicited command-line instructions.
  • Monitor endpoints for suspicious command-line activity, including downloads and archive extraction to ProgramData.
  • Review network traffic for signs of unusual outbound connections, which may indicate the presence of a custom reverse tunnel.
  • Ensure incident response plans are prepared for intrusions involving both user error and advanced persistence mechanisms.

Prompt action and targeted user education are key to reducing the risk from TerminalFix and similar threats.

Originally reported by cybersecuritynews.com.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call