threat-intel TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor Microsoft has disclosed a new ClickFix variant, TerminalFix, that uses fake Cloudflare CAPTCHAs to trick users into executing malicious PowerShell commands via Windows Terminal or PowerShell. The campaign employs a multi-stage attack leveraging DLL sideloading, reconnaissance, and a reverse-tunnel backdoor to gain pers… The Hacker News · 11h ago High clickfixdll sideloadingreverse tunnel