New ClickFix campaign can deploy powerful multi-stage malware directly through Windows Terminal and PowerShell
New ClickFix campaign can deploy powerful multi-stage malware directly through Windows Terminal and PowerShell Microsoft is calling it "TerminalFix" - Microsoft warns of TerminalFix, a campaign abusing compromised sites with fake Cloudflare CAPTCHAs - Victims paste malicious PowerShell commands, sideloading DLLs and deploying a Python implant - Implant enables encrypted reverse tunnels, giving attackers pivot access into internal networks Security researchers from Microsoft are warning of an ongoing malicious campaign that uses compromised websites to trick users into installing a powerful backdoor. Whenever people visited any of the tainted websites, they would see a custom overlay instructing them to complete a fake Cloudflare CAPTCHA verification by copying and running a malicious PowerShell command into Terminal, or PowerShell. Microsoft named the campaign “TerminalFix”, since it is rather similar to the classic ClickFix attack. “While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex, multi-line scripts execute successfully,” the researchers explained. Look for lateral movement Unlike classic ClickFix campaigns that try to deliver simple infostealers, TerminalFix tries to deploy a more complex solution. After running the command in the Terminal, the victim would receive two files - a legitimate binary, and a malicious DLL file. The binary would sideload the malicious DLL which, in turn, delivers a hidden payload called “client.py”. It is a custom Python implant that creates an encrypted WebSocket connection back to the attackers and gives them SOCKS5-style proxy access into the victim’s internal network. In other words, the attackers are deploying a remote-access/network tunneling implant that can connect to internal machines, probe domain controllers, run commands, maintain access after reboots and ultimately use the compromised machine as a pivot point for lateral movement. “This type of intrusion is particularly dangerous because it provides attackers with direct access to an organization’s internal network through the reverse tunnel,” Microsoft explained. “The observed reconnaissance and reverse-tunnel capability could enable an attacker to identify and reach additional systems from a compromised host.” Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Microsoft did not observe the attackers actually carrying out lateral movement, so it is difficult to say what they’re using the access for. Still, the researchers are urging caution: “Organizations should treat affected devices as potential network pivot points and investigate for lateral movement and credential exposure. In the hands-on-keyboard phase that typically follows, attackers leverage this access to escalate privileges, disable security controls, exfiltrate sensitive data, and deploy ransomware across the organization.” ➡️ Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications. You must confirm your public display name before commenting Please logout and then login again, you will then be prompted to enter your display name.
Comments
No comments yet. Start the discussion.