In the ongoing negotiation between human trust and digital deception, Microsoft has identified a campaign called TerminalFix that turns one of the internet's most familiar rituals — the CAPTCHA — into a weapon. By impersonating trusted services like Cloudflare, attackers convince ordinary Windows users to open PowerShell and execute commands that hand over the keys to their machines and, potentially, their entire organization's network. The attack requires no hidden vulnerability, only the willingness of a person to follow instructions that appear to come from a legitimate source — a reminder
Microsoft warns of TerminalFix malware campaign using fake CAPTCHA prompts
A CAPTCHA asking you to open PowerShell is not a CAPTCHA at all.
So the fake CAPTCHA is the hook, but the real attack happens after someone runs the command. What exactly does that command do?
It installs an information stealer and opens a persistent connection back to the attacker. That connection lets them move laterally through the network, access other systems, steal data, or deploy ransomware.
But we're talking about what the command does in theory, right? The source doesn't specify what the actual payload is in these campaigns. We know the mechanism, but not the specific malware families involved.
Why is PowerShell better for the attacker than the Run dialog that ClickFix used?
PowerShell and Command Prompt let you execute multi-line scripts. The Run dialog is more limited. So attackers can do more complex things in a single command, and it's more likely to work.
That's the claim, anyway. Microsoft says it increases the likelihood of success, but there's no data showing how much more successful these campaigns actually are compared to the older version.
Who is most at risk here?
Enterprise networks, primarily. One compromised machine can be a gateway to the whole network. But anyone can fall for it.
Enterprise users, yes—but also people with admin privileges or access to sensitive systems. A regular user with limited permissions causes less damage than a developer or IT person.
What's the defense?
Don't run commands when a website tells you to. Restrict PowerShell access to people who need it. Monitor for unusual command activity. Keep old software off your systems.
Those are the recommendations, but they're not equally practical for everyone. A developer can't work without PowerShell. And monitoring for unusual activity only works if you have the tools and people to actually do the monitoring.
O Pulso
- TerminalFix weaponizes the CAPTCHA — a symbol of routine internet trust — by disguising malicious PowerShell commands as a harmless human-verification step.
- Unlike its predecessor ClickFix, this campaign routes victims through PowerShell or Command Prompt, enabling longer, more complex scripts that dramatically increase the attacker's reach once inside a machine.
- A single employee following the fake instructions can open a persistent backdoor into an enterprise network, creating a launchpad for data theft, lateral spread, or ransomware deployment.
- There is no technical flaw to patch here — the entire attack rests on social engineering, placing employee awareness at the center of any meaningful defense.
- Microsoft has issued mitigation guidance urging organizations to restrict PowerShell access, monitor for unusual command activity, and remind users of a simple rule: no legitimate CAPTCHA will ever ask you to open a terminal.
In the ongoing negotiation between human trust and digital deception, Microsoft has identified a campaign called TerminalFix that turns one of the internet's most familiar rituals — the CAPTCHA — into a weapon. By impersonating trusted services like Cloudflare, attackers convince ordinary Windows users to open PowerShell and execute commands that hand over the keys to their machines and, potentially, their entire organization's network. The attack requires no hidden vulnerability, only the willingness of a person to follow instructions that appear to come from a legitimate source — a reminder that in security, the most exploitable system is often human confidence itself.
Microsoft has identified a malware campaign called TerminalFix that turns the familiar CAPTCHA prompt into a social engineering trap. Fake verification pages — convincingly styled after Cloudflare and other trusted services — instruct Windows users to open PowerShell or Command Prompt and paste in a command to "prove they are human." That command, of course, is anything but benign.
TerminalFix builds on an earlier wave of attacks known as ClickFix, which directed victims to the Windows Run dialog to install information stealers. The key evolution here is the shift to PowerShell and Command Prompt, which allow attackers to run longer, multi-line scripts. Microsoft's threat intelligence team noted this change meaningfully increases the odds that complex commands execute successfully — giving attackers far more flexibility once they are inside.
The consequences of that initial click can extend well beyond a single machine. TerminalFix establishes persistent proxy access through the compromised device, turning it into a potential gateway into the broader corporate network. From there, attackers can steal data, spread malware laterally, or deploy ransomware. The scale of damage depends on the organization's network controls and user permissions — but the breach itself often traces back to one person following instructions on a convincing fake page.
What distinguishes this campaign is its complete reliance on human trust rather than technical exploits. There is no zero-day to patch. The defense, therefore, must be behavioral. Microsoft recommends restricting PowerShell access where feasible, monitoring for unusual command activity, enabling cloud-delivered protection in Microsoft Defender, and auditing environments for outdated software like Flash plugins that create unnecessary exposure.
The clearest signal employees can carry with them: no legitimate CAPTCHA will ever ask someone to open a terminal. The moment a verification screen makes that request, the screen itself is the threat.
Microsoft has identified a new malware campaign that weaponizes one of the internet's most familiar security rituals: the CAPTCHA prompt. The campaign, called TerminalFix, tricks Windows users into believing they need to verify their humanity by opening PowerShell or Command Prompt and pasting in a command. The fake verification pages impersonate Cloudflare and other trusted services, lending them just enough credibility to bypass the skepticism most people have learned to apply to suspicious websites.
This is not a novel attack in isolation. TerminalFix is a refinement of earlier campaigns known as ClickFix, which have circulated among business users for some time. The original ClickFix attacks directed victims to the Windows Run dialog to execute commands that would install information stealers. TerminalFix makes a crucial change: by routing users through PowerShell or Command Prompt instead, attackers gain the ability to execute longer, multi-line scripts. Microsoft's threat intelligence team noted that this shift materially increases the likelihood that complex commands will run successfully, giving attackers more flexibility in what they can accomplish once a machine is compromised.
The real danger emerges after the initial infection. When a user runs the malicious command, TerminalFix initiates a multi-stage intrusion that can grant the attacker persistent proxy access through the compromised machine. That foothold becomes a potential gateway into other parts of a company's network. An attacker with access to an unsecured network could use the initially infected system to steal data, spread malware to other devices, or install ransomware. The scope of damage depends on the victim's network controls, endpoint security, and user permissions—but the initial breach often comes down to a single person following instructions they believed came from a legitimate service.
What makes TerminalFix particularly effective is that it relies entirely on social engineering rather than hidden software exploits. There is no zero-day vulnerability to patch, no obscure technical flaw to close. The attacker simply needs the user to follow the instructions on the fake verification page. This places employee awareness squarely on the front line of defense. A CAPTCHA that asks someone to open PowerShell, Command Prompt, or the Windows Run dialog should trigger immediate suspicion. Legitimate CAPTCHA services do not require users to run system commands to prove they are human. That request is, by definition, abnormal.
Microsoft has published mitigation guidance for organizations. The recommendations include restricting access to PowerShell and the Windows Run dialog where possible, monitoring systems for signs of DLL sideloading, blocking Flash plugins, and enabling cloud-delivered protection in Microsoft Defender Antivirus. These controls come with practical constraints. IT administrators, developers, and other technical users often need access to scripting tools as part of their daily work. Companies can still reduce risk by limiting those tools to users who actually need them and monitoring for unusual command activity that might signal a compromise.
Security teams should also conduct an inventory of older software still installed across their environments. Microsoft's recommendation to block Flash plugins illustrates a broader principle: outdated components that are no longer needed for work can still create additional paths for attackers. The campaign is primarily a concern for enterprise networks, where one compromised device can provide a path to more valuable systems and data. But the basic principle applies to individual users as well. Do not run a PowerShell or Command Prompt command simply because a website asks you to, especially when the request is framed as a CAPTCHA or security check. The moment someone asks you to open a terminal to verify you are human, you are no longer dealing with a legitimate security measure.
Citações Notáveis
The change increases the likelihood that complex, multi-line scripts execute successfully.— Microsoft Threat Intelligence
Legitimate CAPTCHA services do not require users to run system commands to prove they are human.— Microsoft security guidance