<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/fake-cloudflare-captcha-tricks-victims-into-opening-a-tunnel-for-attackers-gtqaorplr" -->

---
title: Fake Cloudflare CAPTCHA tricks victims into opening a...
description: Microsoft Threat Intelligence detailed a campaign called TerminalFix, a variant of the ClickFix technique, that uses fake Cloudflare CAPTCHA prompts on...
canonical: https://daily.dev/posts/fake-cloudflare-captcha-tricks-victims-into-opening-a-tunnel-for-attackers-gtqaorplr
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Fake Cloudflare CAPTCHA tricks victims into opening a tunnel for attackers | daily.dev
og:description: Microsoft Threat Intelligence detailed a campaign called TerminalFix, a variant of the ClickFix technique, that uses fake Cloudflare CAPTCHA prompts on...
og:url: https://daily.dev/posts/fake-cloudflare-captcha-tricks-victims-into-opening-a-tunnel-for-attackers-gtqaorplr
og:image: https://api.daily.dev/og/posts/GTqAOrPLr.png
og:image:alt: Fake Cloudflare CAPTCHA tricks victims into opening a tunnel for attackers
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Fake Cloudflare CAPTCHA tricks victims into opening a tunnel for attackers

**[CSO Online](https://daily.dev/sources/csoonline)** · 3 min read · 0 upvotes · 0 comments

## Summary

Microsoft Threat Intelligence detailed a campaign called TerminalFix, a variant of the ClickFix technique, that uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal or PowerShell rather than the Run dialog. The resulting attack chain involves DLL sideloading via a legitimate binary and a malicious DLL, payloads hidden in PNG images via steganography, persistence through Registry Run keys and scheduled tasks, Active Directory reconnaissance, and a final custom Python-based reverse-tunnel implant that opens an encrypted WebSocket connection giving attackers SOCKS-style proxy access into the victim's network. Microsoft published detection coverage, IOCs, hunting queries and mitigation guidance.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.csoonline.com/article/4216927/fake-cloudflare-captcha-tricks-victims-into-opening-a-tunnel-for-attackers.html>

## Questions this post answers

### What is the TerminalFix attack and how does it use fake Cloudflare CAPTCHA prompts?

TerminalFix is a ClickFix variant campaign identified by Microsoft Threat Intelligence that displays a fake Cloudflare verification overlay on compromised websites, tricking visitors into copying and running a malicious PowerShell command in Windows Terminal or PowerShell rather than the Run dialog, enabling more complex multi-line scripts to execute successfully.

_Security teams tracking ClickFix-style social engineering campaigns can follow evolving threat intel on daily.dev._

### How does the TerminalFix malware achieve persistence and hide its payloads on a compromised Windows system?

The malware sideloads a malicious DLL named dui70.dll through a legitimate binary called LockScreenContentServer.exe, then downloads additional payloads hidden inside PNG images using steganography. Persistence is established through both Registry Run keys and scheduled tasks, giving the malware multiple ways to survive on the infected system.

_Incident responders investigating DLL sideloading and steganographic payloads can dig deeper via daily.dev._

### What does the reverse-tunnel implant in the TerminalFix campaign allow attackers to do?

The final payload is a custom Python-based reverse-tunnel implant, launched invisibly via pythonw.exe, that opens an encrypted WebSocket connection to attacker infrastructure, granting full SOCKS-style TCP proxy access through the compromised host. Combined with Active Directory reconnaissance, this can let attackers use the infected device as a bridge to reach additional internal systems.

_Network defenders assessing reverse-tunnel and lateral movement risks can stay current via daily.dev._

## Similar posts on daily.dev

- [ClickFix techniques evolve in new infostealer campaigns](https://daily.dev/posts/clickfix-techniques-evolve-in-new-infostealer-campaigns-mufrpsfhw) · CSO Online · 0 upvotes · 0 comments
- [Fake Google and Cloudflare verification pages spread multiple malware families](https://daily.dev/posts/fake-google-and-cloudflare-verification-pages-spread-multiple-malware-families-8s8xqrwfw) · Security Boulevard · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#malware](https://daily.dev/tags/malware), [#powershell](https://daily.dev/tags/powershell), [#active-directory](https://daily.dev/tags/active-directory)

[View this post on daily.dev](https://daily.dev/posts/fake-cloudflare-captcha-tricks-victims-into-opening-a-tunnel-for-attackers-gtqaorplr)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Fake Cloudflare CAPTCHA tricks victims into opening a tunnel for attackers","url":"https://daily.dev/posts/fake-cloudflare-captcha-tricks-victims-into-opening-a-tunnel-for-attackers-gtqaorplr","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/fake-cloudflare-captcha-tricks-victims-into-opening-a-tunnel-for-attackers-gtqaorplr"},"datePublished":"2026-09-01T11:22:23.867Z","dateModified":"2026-09-01T11:22:48.776Z","description":"Microsoft Threat Intelligence detailed a campaign called TerminalFix, a variant of the ClickFix technique, that uses fake Cloudflare CAPTCHA prompts on...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/56dc0681b8ed92435c2a4a733bebbda4?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/56dc0681b8ed92435c2a4a733bebbda4?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"CSO Online","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"CSO Online","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/98667e4b5cac46cf9c470819c6cf71cd","url":"https://daily.dev/sources/csoonline"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/fake-cloudflare-captcha-tricks-victims-into-opening-a-tunnel-for-attackers-gtqaorplr","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,malware,powershell,active-directory","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"CSO Online","item":"https://daily.dev/sources/csoonline"},{"@type":"ListItem","position":3,"name":"Fake Cloudflare CAPTCHA tricks victims into opening a tunnel for attackers"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/fake-cloudflare-captcha-tricks-victims-into-opening-a-tunnel-for-attackers-gtqaorplr#faq","mainEntity":[{"@type":"Question","name":"What is the TerminalFix attack and how does it use fake Cloudflare CAPTCHA prompts?","acceptedAnswer":{"@type":"Answer","text":"TerminalFix is a ClickFix variant campaign identified by Microsoft Threat Intelligence that displays a fake Cloudflare verification overlay on compromised websites, tricking visitors into copying and running a malicious PowerShell command in Windows Terminal or PowerShell rather than the Run dialog, enabling more complex multi-line scripts to execute successfully. Security teams tracking ClickFix-style social engineering campaigns can follow evolving threat intel on daily.dev."}},{"@type":"Question","name":"How does the TerminalFix malware achieve persistence and hide its payloads on a compromised Windows system?","acceptedAnswer":{"@type":"Answer","text":"The malware sideloads a malicious DLL named dui70.dll through a legitimate binary called LockScreenContentServer.exe, then downloads additional payloads hidden inside PNG images using steganography. Persistence is established through both Registry Run keys and scheduled tasks, giving the malware multiple ways to survive on the infected system. Incident responders investigating DLL sideloading and steganographic payloads can dig deeper via daily.dev."}},{"@type":"Question","name":"What does the reverse-tunnel implant in the TerminalFix campaign allow attackers to do?","acceptedAnswer":{"@type":"Answer","text":"The final payload is a custom Python-based reverse-tunnel implant, launched invisibly via pythonw.exe, that opens an encrypted WebSocket connection to attacker infrastructure, granting full SOCKS-style TCP proxy access through the compromised host. Combined with Active Directory reconnaissance, this can let attackers use the infected device as a bridge to reach additional internal systems. Network defenders assessing reverse-tunnel and lateral movement risks can stay current via daily.dev."}}]}
```

