# TerminalFix campaign deploys a reverse tunnel through multistage intrusion

DevFeed: [TerminalFix campaign deploys a reverse tunnel through multistage intrusion](<https://devfeed.tech/articles/terminalfix-campaign-deploys-a-reverse-tunnel-through-multistage-intrusion-7636.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/>)

Author: Microsoft Security Research, Sagar Patil, Suriyaraj Natarajan and Parasharan Raghavan

Published: 2026-08-29T03:43:27Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [c2](<https://devfeed.tech/tags/c2.md>), [clickfix](<https://devfeed.tech/tags/clickfix.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [python](<https://devfeed.tech/tags/python.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [security](<https://devfeed.tech/tags/security.md>), [windows](<https://devfeed.tech/tags/windows.md>)

## AI overview

Microsoft analyzes the TerminalFix ClickFix campaign, which uses a fake Cloudflare CAPTCHA to induce PowerShell execution and deploys a multi-stage intrusion chain. The chain includes DLL sideloading, steganographic payload delivery, Active Directory reconnaissance, persistence, and an encrypted reverse tunnel that can provide access into the compromised network.

## Source excerpt

Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance. The post TerminalFix campaign deploys a reverse tunnel through multistage intrusion appeared first on Microsoft Security Blog.