Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issues › Volume 342, Issue 5 › IT Vendor News › ExtraHop

Anatomy of an Attack: TerminalFix: When a Workstation Becomes a Network Pivot

ExtraHop, Thursday, October 1st, 2026

ExtraHop breaks down TerminalFix, a ClickFix variant that uses fake Cloudflare checks and Windows Terminal to pivot into networks.

TerminalFix, a ClickFix variant reported by Microsoft in August, lures victims with a fake Cloudflare human verification check into running a copied command in PowerShell or Windows Terminal.

Execution triggers a multi-stage intrusion with DLL sideloading, hidden payloads, persistence, Active Directory discovery and a reverse C2 tunnel.

ExtraHop cites a German BSI advisory about a state institution compromise matching the technique and explains how network detection can spot the workstation-to-network pivot.

more →  ·  More from ExtraHop →