- What: New campaign uses PowerShell for enterprise attacks
- Impact: Organizations may be targeted through social engineering and network infiltration
Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources THREAT INTELLIGENCE CYBERATTACKS & DATA BREACHES DATA PRIVACY IDENTITY & ACCESS MANAGEMENT SECURITY NEWS 'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations' networks. Alexander Culafi,Senior News Writer,Dark Reading August 31, 2026 4 Min Read SOURCE: THINK_ABOUT_LIFE VIA GETTY IMAGES An emerging ClickFix-style campaign tricks users into opening PowerShell and executing a malicious command, kicking off a complex attack chain designed to establish a foothold inside enterprise networks. Threat actors in recent years have increasingly relied on ClickFix for social engineering campaigns. Generally, a user visits a compromised or attacker-controlled website, only to be told they need to paste a command into Windows Run or MacOS's Terminal. The command usually connects to an attacker-controlled server, which typically downloads and installs infostealers or other types of malware. The reason it's called ClickFix is that the victim is typically presented with instructions to "fix" a problem, complete a verification step, or troubleshoot a browser issue by running a command supplied by the attacker. One variant sees the attacker drawing potential victims into a fake Zoom call through a browser; technical problems arise with sound or video, and victims are told they must paste a command to fix the issue. Related:Interpol's Jackal IV Disrupts West African Crime Infrastructure Microsoft recently detailed a ClickFix-variant campaign the company dubbed "TerminalFix," in which attackers deploy fake Cloudflare CAPTCHA overlays at the start of a "sophisticated" attack chain. In order to complete the CAPTCHA, the user is told to open Windows Terminal or PowerShell and paste a malicious command (which was silently copied to the clipboard) within. Although Terminal and PowerShell aren't technically the same thing, modern Windows installs open Terminal into PowerShell by default. While attackers can use Windows Run to launch a short downloader that retrieves additional payloads, Microsoft argues that directing users into PowerShell increases the likelihood that longer, more complex scripts execute successfully. This complexity facilitates attacks against larger enterprises easier than a "straightforward" ClickFix attack would, which stands to reason, as the campaign targets organizations across multiple industries, according to Microsoft researchers. A Single Command Leads to a Complex Attack Chain As for this specific campaign, the initial PowerShell command downloads and launches a zip archive containing a malicious DLL for sideloading, which kicks off the rest of the attacker's complex attack chain. It downloads payloads concealed inside PNG images, establishes dual persistence through Registry Run keys and scheduled tasks, conducts domain reconnaissance, and deploys a "Python-based reverse-tunnel C2 implant that tunnels arbitrary TCP traffic back through an encrypted WebSocket channel to attacker infrastructure," according to the Microsoft's blog post. Related:Tricky 'SynkLoader' Multitool May Herald Ransomware Microsoft researchers noted the campaign was "particularly dangerous" because the reverse tunnels give the threat actors direct access to the victim organizations' internal networks. "In the hands-on-keyboard phase that typically follows, attackers leverage this access to escalate privileges, disable security controls, exfiltrate sensitive data, and deploy ransomware across the organization," the researchers wrote. "The combination of stealth techniques (DLL sideloading, steganography, hidden folders) and persistent network access make this TerminalFix campaign a serious threat to enterprise environments." The TerminalFix naming, however, has drawn some skepticism. While Microsoft describes TerminalFix as a variant of ClickFix, Proofpoint senior threat researcher Tommy Madjar argues that the use of Terminal windows dates back to some of the earliest ClickFix activity documented in 2024. "A terminal can accept longer, multiline scripts," he tells Dark Reading, "but the same multistage intrusion could just as easily begin with a short command pasted into Run that retrieves the next stage. Combined with the basic HTML lure and execution flow, Microsoft’s example does not stand out from established clusters such as ClearFake or ErrTraffic." Related:SilkParasite Threatens Central Asian Orgs With Flurry of RATs Defending Against TerminalFix and Other ClickFix Attacks Microsoft's blog post makes a number of recommendations to users. For one, organizations should restrict PowerShell and Run dialog execution for standard users through methods like Group Policy, Application Control for Windows, or AppLocker. Organizations may also want to restrict the Windows Run dialog where not required for daily work and monitor for DLL sideloading indicators. And because ClickFix is a social engineering tactic, it may also be wise to educate employees on how attackers deploy such attacks so users can identify them. Madjar specifically emphasizes this last part and argues that wide restrictions on Run dialog and Terminal access are "rarely practical." "Many legitimate software installations rely on users executing commands directly in a terminal. Claude Code is a current example: its recommended installation method downloads and executes code without first asking the user to inspect it," he says. "Defenses should therefore focus on training users not to execute commands copied from untrusted websites, blocking malicious sites before users reach them, and detecting suspicious execution when prevention fails." About the Author Alexander Culafi Senior News Writer, Dark Reading Alex is an award-winning writer, journalist, and podcast host based in Boston. After cutting his teeth writing for independent gaming publications as a teenager, he graduated from Emerson College in 2016 with a Bachelor of Science in journalism. He has previously been published on VentureFizz, Search Security, Nintendo World Report, and elsewhere. At Dark Reading, he covers a variety of cybersecurity topics, including the cybercrime ecosystem, open source security, and the intersection between AI and threat actors. In his spare time, Alex hosts the weekly Nintendo podcast, "Talk Nintendo Podcast," and works on personal writing projects, including two previously self-published science fiction novels. He has received numerous awards, including TechTarget's Writer of the Year in 2022 as well as more than 10 Azbee awards for his reporting between 2022 and today. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars How to Leverage Threat Intelligence Without Drowning: The Zero Noise Approach Cloud Incident Response: Forensics in Distributed Environments Beyond the Login: Key Considerations for Evaluating Identity Security SASE Pivot and Trends 2026: A Gartner Keynote What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI More Webinars You May Also Like THREAT INTELLIGENCE Hackers Target Cybersecurity Firm Outpost24 in 7-Stage Phish by Jai Vijayan MAR 17, 2026 THREAT INTELLIGENCE Iran's Cyber-Kinetic War Doctrine Takes Shape by Alexander Culafi MAR 06, 2026 THREAT INTELLIGENCE React2Shell Exploits Flood the Internet as Attacks Continue by Rob Wright DEC 12, 2025 THREAT INTELLIGENCE Chinese Gov't Fronts Trick the West to Obtain Cyber Tech by Nate Nelson OCT 06, 2025 Featured Check out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show! Editor's Choice CYBER RISK What We Missed: Delta Flight Disrupted With Wi-Fi Hack byRob Wright,Alexander Culafi AUG 20, 2026 CYBERATTACKS & DATA BREACHES Agentic AI Presents New Insider Threat Model for Orgs AUG 19, 2026 CYBERSECURITY OPERATIONS Mission-Driven Security: Inside a Global Bank's Defense byKristina Beek AUG 14, 2026 Want more Dark Reading stories in your Google search results? HOW ORGANIZATIONS ARE MANAGING INCIDENT RESPONSE Nearly every organization faced a critical security incident last year, but most weren't equipped to contain it. Get the full findings in this free report. DOWNLOAD NOW NOVEMBER 12, 2026 | VIRTUAL What Every Enterprise Should Know About Securing Cloud Assets In the Age of AI SAVE YOUR SPOT Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices