TerminalFix campaign deploys a reverse tunnel through multistage intrusion

    Date: 08/31/2026

    Severity: High

    Summary

    The TerminalFix campaign is a sophisticated ClickFix variant that uses compromised websites and fake Cloudflare CAPTCHA lures to trick victims into executing malicious PowerShell commands through Windows Terminal. The multi-stage attack chain combines DLL sideloading, PNG steganography, Registry Run key and scheduled task persistence, Active Directory reconnaissance, and hidden directories. It ultimately deploys a custom Python-based reverse-tunnel backdoor implant that uses encrypted WebSocket/TLS communication to provide attackers with SOCKS-style network access through the compromised host. 

    Indicators of Compromise (IOC) List 

    Domain/URLs

    bestsocialmedianewspapper.com

    gitnow.dev

    offlineupdater.com

    https://linked-log.com/

    Hash

    026478003fe354134c03acf6890e7d3b153ba08a836eca42350db48f213872ab

    032b529fac61e550f5dc9489686f519b82d64625fa05a8d9ecf8ba8be9b2ad22

    18c2090e8a0ae0568af9b87e59eaf8270f23d2909600ed9db91a9444fd8b278f

    342df92235c9dec81203b837addaa38bb85b64b4a48fe71b5303ca86d991991e

    5d43abf5c36ea203176d3300ff14af27b4be81810ad2679b3a62b255e3d6e1c8

    9a7b4dcd51d9251c177d323d6aaecdfc86674f69bc1af048dc872926d22aaa24

    b8d107800403b9197e5b7609ceacd8e4cac1b0f9a1d156e6dacd6c3f7794b36a

    ba77feed86bcda49308746421bdc684a432dd5d68c363975b2a3c6831bda3f07

    df8221a933b38284ebdcb8bffc2df62123c9f5b5f421dd0b070e13e668b3eabf

    eb1b4be34d05b394fb74efdeb95faecd1d1963be6ecc1b9db2b4757b491f01f0

    ededeacf30e493dd632d477fe770ba419aa2848f685ea049381a0a8d2cc3e84d

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "gitnow.dev" or url like "gitnow.dev" or siteurl like "gitnow.dev" or domainname like "https://linked-log.com/" or url like "https://linked-log.com/" or siteurl like "https://linked-log.com/" or domainname like "bestsocialmedianewspapper.com" or url like "bestsocialmedianewspapper.com" or siteurl like "bestsocialmedianewspapper.com" or domainname like "offlineupdater.com" or url like "offlineupdater.com" or siteurl like "offlineupdater.com"

    Detection Query 2 :

    sha256hash IN ("9a7b4dcd51d9251c177d323d6aaecdfc86674f69bc1af048dc872926d22aaa24","18c2090e8a0ae0568af9b87e59eaf8270f23d2909600ed9db91a9444fd8b278f","b8d107800403b9197e5b7609ceacd8e4cac1b0f9a1d156e6dacd6c3f7794b36a","eb1b4be34d05b394fb74efdeb95faecd1d1963be6ecc1b9db2b4757b491f01f0","ba77feed86bcda49308746421bdc684a432dd5d68c363975b2a3c6831bda3f07","342df92235c9dec81203b837addaa38bb85b64b4a48fe71b5303ca86d991991e","5d43abf5c36ea203176d3300ff14af27b4be81810ad2679b3a62b255e3d6e1c8","026478003fe354134c03acf6890e7d3b153ba08a836eca42350db48f213872ab","ededeacf30e493dd632d477fe770ba419aa2848f685ea049381a0a8d2cc3e84d","032b529fac61e550f5dc9489686f519b82d64625fa05a8d9ecf8ba8be9b2ad22","df8221a933b38284ebdcb8bffc2df62123c9f5b5f421dd0b070e13e668b3eabf")

    Reference: 

    https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/           


    Tags

    MalwareBackdoorClickFixPowerShell AttackDLLSideLoadingSteganographyActive DirectoryPythonWebSocket

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags