Skip to main content
institutional access

You are connecting from
Lake Geneva Public Library,
please login or register to take advantage of your institution's Ground News Plan.

Published loading...Updated

PNG Pixels Mask Reverse Tunnel: How TerminalFix Turns Images Into Enterprise Network Backdoors

Summary by WebProNews
Microsoft has exposed TerminalFix, a ClickFix evolution that tricks users into running PowerShell which sideloads a DLL, extracts malware from steganographic PNGs, maps Active Directory, and installs a custom Python reverse WebSocket tunnel for network-wide proxy access. The multi-stage attack deletes evidence and builds redundant persistence.

9 Articles

Microsoft alerts to TerminalFix, a new attack that uses fake CAPTCHAs, image steganography, and PowerShell to create reverse tunnels on networks.

TerminalFix is a new variant of cyberattack that uses fake Cloudflare verification pages to trap Internet users. By encouraging the victim to paste a PowerShell command, this code deploys stealth access to the company's servers. The ultimate goal is to use the infected machine as an invisible bridge to infiltrate the entire internal network.

Read Full Article

Microsoft warns that TerminalFix attacks deploy reverse tunnels.

Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

Cyber Security News broke the news on Monday, August 31, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal