New TerminalFix Campaign Attacks via Fake CAPTCHAs and Installs Backdoors


Microsoft has revealed information of a new ClickFix version, called TerminalFix, that intends to lure users into launching a malicious command in PowerShell or Windows Terminal. 

TerminalFix is attacking organizations across various industries. 

About the ClickFix campaign

The campaign deploys hacked websites to show a fake Cloudflare CAPTCHA authentication overlay that lures users into copying and running a malicious PowerShell command. 

Although traditional ClickFix campaigns send victims to the Windows Run dialog, TerminalFix campaigns use the same tactic but send users to PowerShell or TerminalFix instead. This increases the execution of complex, multi-line scripts successfully. 

Attack tactic

Contrary to earlier ClickFix versions that usually deploy a single infostealer, this TerminalFix campaigns uses an advanced multi-stage attack chain that integrates “DLL sideloading, steganographic payload extraction, extensive Active Directory reconnaissance, and a custom reverse-tunnel implant – giving the attacker persistent, network-level proxy access through the compromised host,” said Microsoft. 

After execution, the Powershell commands mimics as a Cloudflare authentication process while downloading a ZIP archive which contains an authentic binary and a compromised DLL used for sideloading. 

DLL sideloading

The sideloaded DLL initiates a detailed second stage, downloading payloads hidden inside PNG images via steganography, creating dual persistence via scheduled tasks and Registry Run key, doing robust domain reconnaissance. Lastly, it deploys a Python-based reverse-tunnel C2 implant that channels arbitrary TCP traffic back via an encoded WebSocket channel to threat actor infrastructure. 

This type of invasion can be dangerous as it offers threat actors with direct access to a firm’s internal network via the reverse tunnel. 

The reverse-tunnel capability and discovered reconnaissance could allow a threat actor to locate and reach additional systems from an infected host. According to Microsoft, firms should treat impacted devices as possible network pivot points and look out for credential exposure and  lateral movement. 

Implications

Threat actors can use this access to disable security controls, deploy ransomware across the organization, escalate privileges, and exfiltrate sensitive data. 

The mix of stealth tactics such as hidden folders, DLL sideloading, steganography and persistent network access result in this TerminalFix campaign a real danger to enterprise environments.

According to Microsoft,  “Customers can use Microsoft Defender XDR Threat analytics and related Microsoft threat intelligence reporting to stay current on the malicious activity, indicators, detection coverage, and recommended response actions associated with this compromise.”

This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents

Read the original article: