Anatomy of an Attack: TerminalFix: When a Workstation Becomes a Network Pivot
ExtraHop, Thursday, October 1st, 2026
ExtraHop breaks down TerminalFix, a ClickFix variant that uses fake Cloudflare checks and Windows Terminal to pivot into networks.
TerminalFix, a ClickFix variant reported by Microsoft in August, lures victims with a fake Cloudflare human verification check into running a copied command in PowerShell or Windows Terminal.
Execution triggers a multi-stage intrusion with DLL sideloading, hidden payloads, persistence, Active Directory discovery and a reverse C2 tunnel.
ExtraHop cites a German BSI advisory about a state institution compromise matching the technique and explains how network detection can spot the workstation-to-network pivot.