Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Le leurre, nommé TerminalFix, hébergé sur linked-log[.]com, simulait une vérification Cloudflare Turnstile et écrivait du PowerShell dans le presse-papiers.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware establishes persistence through... a scheduled task that runs every 60 minutes...
„… gefälschte Captcha-Abfragen Nutzende zur Ausführung von Terminal- oder PowerShell-Befehlen.“
« écrivait du PowerShell dans le presse-papiers » ; « coller la commande (Ctrl+V, Entrée) » dans Windows Terminal.
The malware installs a legitimate, signed Python runtime directly from python.org and launches the tunnel... via pythonw.exe.
„Dabei verleiten gefälschte Captcha-Abfragen Nutzende zur Ausführung von Terminal- oder PowerShell-Befehlen.“
„Der Code darin lädt PNG-Bilddateien von den Angreifern herunter, in denen per Steganografie weitere Programme und DLLs versteckt sind.“
A DLL disguised as the Windows DirectUI Engine, dui70.dll... [is] alongside a legitimate signed LockScreenContentServer.exe executable.
“The first eight bytes specify the embedded file’s length, while the remaining data is reconstructed into an executable and two DLL fragments, which are joined on the victim’s disk.”
[The malware performs] Active Directory... computer enumeration, and ping[s] a list of named servers across common infrastructure roles... to map accessible assets.
The final payload is the custom Python-based reverse tunnel implant that connects outbound over TLS port 443 and upgrades to a WebSocket...
„Diese richten auch einen SOCKS-Proxy ein, haben also durch einen Tunnel Zugriff auf das Netz der attackierten Organisation.“
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ClickFix-style phishing lure that impersonates a Cloudflare Turnstile check and persuades victims to paste and execute a PowerShell command in Windows Terminal, initiating the compromise chain.
Campagne ClickFix multi-étapes qui compromet des sites légitimes et abuse de Windows Terminal ou PowerShell pour exécuter une chaîne d'intrusion. Elle télécharge une archive ZIP, effectue un chargement latéral de DLL, reconstruit des charges utiles cachées dans des images PNG par stéganographie, établit une persistance par clé Run et tâche planifiée, réalise de la reconnaissance Active Directory, puis déploie un tunnel inverse TLS/WebSocket permettant un proxy TCP/SOCKS5 vers le réseau interne.
A ClickFix-derived social-engineering attack chain that tricks victims into executing PowerShell commands. It uses DLL sideloading and steganographically concealed payloads, establishes persistence through Registry Run keys and scheduled tasks, performs Active Directory reconnaissance, and deploys a Python reverse-tunnel backdoor that proxies arbitrary TCP traffic through an encrypted WebSocket channel to attacker-controlled infrastructure.
TerminalFix is a ClickFix-based intrusion campaign that uses fake Cloudflare CAPTCHA prompts to induce execution of malicious PowerShell. It downloads a ZIP containing a legitimate executable and rogue DLL for DLL sideloading, extracts later payloads from PNG steganography, establishes Registry Run-key and scheduled-task persistence, conducts Active Directory and network reconnaissance, and deploys a Python reverse-tunnel backdoor (client.py). The backdoor uses encrypted WebSockets to tunnel arbitrary TCP traffic, allowing attacker infrastructure to access hosts reachable from the compromised machine.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.