Microsoft Threat Intelligence is warning about a TerminalFix campaign that extends the familiar ClickFix tactic: a fake Cloudflare CAPTCHA page tricks users into running a copied terminal command themselves. For small and midsized businesses, this matters because the attack does not stop at a simple infostealer after first execution. Microsoft describes a multistage chain with sideloading, Active Directory reconnaissance, and a reverse tunnel that can turn the compromised device into an internal access point.
What Microsoft reported on 29 August 2026
The analysis was published on the Microsoft Security Blog and describes TerminalFix as a variant of ClickFix. The lure is a compromised website that displays a fake Cloudflare Turnstile verification prompt. When the user interacts with it, a supposed verification command is copied to the clipboard; the page then instructs the user to run it in Windows Terminal or PowerShell. Microsoft explains that this variant can be more reliable than simpler ClickFix flows because Terminal or PowerShell can execute complex, multi-line scripts.
The downloaded package includes a legitimate Windows Lock Screen binary and a malicious DirectUI component, according to Microsoft. The legitimate Windows binary is abused as a sideloading host. The follow-on script then retrieves additional payloads from PNG images, establishes persistence through autostart and a scheduled task, and starts a tunnel component.
Why this affects smaller organizations
Many organizations with 10 to 250 seats already use Microsoft Defender, but they do not run a continuously staffed SOC. That makes a clear response path important: TerminalFix relies on user deception, script execution, and normal Windows components. These are not exotic edge cases; they are everyday endpoints and administration tools. If alerts from Microsoft Defender are reviewed only occasionally, the move from a single endpoint infection to internal reconnaissance can be missed.
- The initial access path is a website and a seemingly harmless CAPTCHA instruction.
- Execution happens through a user-pasted command rather than a traditional email attachment.
- The malware chain looks for domain information, administrator groups, and servers.
- The reverse tunnel can provide network access from the compromised device’s point of view.
Deadline and urgency: review now, not at a later date
Microsoft does not publish a migration or retirement deadline for TerminalFix. The urgency comes from Microsoft’s active observation of the campaign and the published indicators of compromise. This is therefore not a topic to park for a later project; it calls for a timely control review. Device events, network connections, and script execution should be checked now against Microsoft’s guidance. One Microsoft note is especially important: organizations that find related indicators should treat affected hosts as possible pivot points and investigate for lateral movement and credential exposure.
Technical signals Defender can expose
Microsoft maps the activity to several Defender detections. These include possible ClickFix or TerminalFix script activity, unexpected loading of a DirectUI component, suspicious scheduled tasks, Active Directory enumeration, and possible proxy or tunneling tool use. For Microsoft Defender for Endpoint, Microsoft also publishes Advanced Hunting queries, including searches for suspicious script execution into temporary system paths, sideloading from non-standard paths, and outbound connections to known command servers.
The nuance matters: Microsoft explicitly states that downstream actions such as ransomware deployment were not observed in the analyzed chain. Even so, the combination of reconnaissance, persistence, and tunnel access is enough reason to treat a single hit as more than a cleanup task. It should trigger an incident review.
Concrete next steps for administrators
- Run the Microsoft-published Defender XDR Advanced Hunting queries for script execution, sideloading, and network indicators.
- Treat the Windows Lock Screen binary named in Microsoft’s post outside its standard system path as suspicious.
- Review network protection, web protection, SmartScreen, cloud-delivered protection, and suitable attack surface reduction rules.
- Enable enhanced script logging and assess constrained execution modes where standard users do not need to run scripts.
- If there are hits, rotate credentials, especially when the host was domain-joined or privileged accounts were used.
For a Microsoft Security Assessment, TerminalFix is a useful test case: do logging, endpoint protection, web filtering, and response processes work together, or does visibility stop after the first antivirus alert?
Official Microsoft sources
- Microsoft Security Blog: TerminalFix campaign deploys a reverse tunnel through multistage intrusion
- Microsoft Learn: Network protection in Microsoft Defender for Endpoint
If you want to know whether your environment can surface TerminalFix signals and whether the recommended protections are actually enabled, we can review your Microsoft 365 security configuration in a focused assessment – get in touch.
What does this mean for your environment?
Assess the topic in the context of your Microsoft 365 environment and define a practical next step.

You speak directly with Sebastian Kerssen – working in the Microsoft ecosystem since 2014, with personal consulting and a dedicated point of contact.
