TerminalFix: Fake CAPTCHA Prompts Target Windows Users

What happened
Microsoft has issued a warning about a new attack campaign nicknamed TerminalFix, according to reporting from BleepingComputer. It is the latest twist on the "ClickFix" social-engineering pattern: a compromised website shows what looks like a routine Cloudflare CAPTCHA or human-verification prompt, then instructs the visitor to copy and paste a command into Windows Terminal to "finish" the check. The pasted command is malicious PowerShell, and the reporting describes the campaign deploying reverse tunnels, which give an attacker a path back into the machine and the network around it.
The important detail is where the trickery lives. There is no exploit to patch and no malicious attachment to quarantine. The victim does the work: they open Windows Terminal themselves and run the command themselves, on a device they are already signed into. Specific indicators, affected domains, and the full payload chain are still emerging, so treat any list of "the" TerminalFix domains as incomplete and verify details against Microsoft's own advisory rather than assuming coverage from a single blocklist.

Why this matters for Pittsburgh small and mid-sized businesses
If you run a 10-to-200-person firm in Western PA, this attack is aimed squarely at how your people actually work. Fake CAPTCHAs show up during ordinary browsing: a county records lookup, a vendor portal, a shipping tracker, a continuing-education site. Nobody thinks twice about clicking "verify you are human." And the instruction to paste a command feels plausible to staff who have been walked through similar steps by a help desk before.
The industry mix around here makes the stakes uneven. For an accounting or CPA firm mid-engagement, a reverse tunnel on one workstation is a straight line to client tax data and to FTC Safeguards obligations. For a law firm, it is privileged matter files. In healthcare, a single compromised endpoint that touches ePHI turns into a HIPAA risk-analysis and breach-assessment exercise, whether or not data ultimately moved. For defense contractors and their suppliers along the river valleys, an interactive foothold on a machine that stores or processes CUI is exactly the scenario CMMC Level 2 controls exist to prevent, and it is the kind of incident that carries reporting expectations under your contract terms.
Manufacturers have a different exposure: shop-floor and engineering PCs are often local-admin by convention, lightly monitored, and shared. Those are the machines where a pasted command runs with the fewest guardrails.
There is also a plain-language reason this technique keeps working. Most security awareness training teaches "don't click links" and "don't open attachments." TerminalFix asks for neither. Your training content is probably a step behind the threat, and that gap is worth closing this month rather than at your next annual renewal.
What to do about it this week
- Send a short, specific staff advisory today. One paragraph, plain English: no legitimate website, CAPTCHA, or verification screen will ever ask you to open Windows Terminal, PowerShell, or the Run box and paste a command. If a site asks, close the tab and report it. Skip the 20-minute module for now, get the sentence in front of everyone.
- Restrict PowerShell and Windows Terminal for users who don't need them. Most sales, admin, clinical, and billing staff have never intentionally opened a terminal. Use application control or AppLocker-style policies to block or limit interactive PowerShell for those groups, and enable script block logging and transcription where you allow it. Verify your current policy state before assuming it is already covered.
- Confirm your EDR is actually alerting on this pattern. Ask your provider to show detections for browser processes spawning terminal or PowerShell children, and for outbound tunneling tools. If your EDR is deployed but nobody is watching alerts after 5 p.m., that is the gap to fix, not the tooling.
- Kill standing local admin rights. A pasted command running as a standard user is a bad day. The same command running as local admin is an incident report. Move to on-demand elevation and confirm coverage across laptops that rarely check in.
- Look for the outbound side. Reverse tunnels need egress. Review firewall and DNS logs for unusual long-lived outbound connections from workstations, and restrict egress from servers and any systems in your CUI or ePHI scope to what is genuinely required.
- Make reporting frictionless and blame-free. Publish one channel, a phone number or a "report phishing" button, and say out loud that anyone who pastes something and then feels uneasy should call immediately. Minutes matter with an interactive foothold, and fear of embarrassment costs hours.
- Re-check your incident response contacts and clocks. With today's date, work backward from your obligations: who declares an incident, who notifies clients, and what your regulator or contract requires. If you handle CUI, confirm your DFARS 7012 reporting path and credentials work before you need them.
Two adjacent items worth putting on the roadmap: if your team is experimenting with AI tools, an acceptable-use policy should explicitly cover "never run commands an AI assistant or website gives you without verification," and any document automation touching regulated data belongs in a reviewed design, not a browser tab.
How we help
PGH Networks handles the unglamorous work that makes this attack fail: patch management and endpoint hardening, application control and admin-rights cleanup, monitored detection and response, Microsoft 365 configuration and log retention, and awareness training that keeps pace with what attackers are actually doing. Our vCIO team ties all of it to the framework you answer to, whether that is HIPAA, SOC 2, FTC Safeguards, or CMMC.
Want us to check whether interactive PowerShell is blocked for your non-technical staff right now? Call 724.888.7007 or reach us through the contact form and we will take a look this week.
Related reading

PaperCut Zero-Day: What Pittsburgh SMBs Need to Patch Now
PaperCut NG/MF is under active zero-day exploitation. Here's what Pittsburgh SMBs should verify and patch this week, and how to reduce future exposure.

CISA Orders Urgent Zimbra Patch: What Pittsburgh SMBs Should Do
CISA ordered urgent patching of an actively exploited Zimbra flaw. Here is what Pittsburgh SMBs running Zimbra should do this week to stay ahead of attackers.

Defender's Own Boot Driver Can Be Turned Against You
Check Point Research shows Microsoft Defender's BTR.sys driver can be abused to wipe security tools at boot. What Pittsburgh SMBs should do this week.