Microsoft Threat Intelligence
Microsoft Security Research is investigating a TerminalFix campaign, a variant of the ClickFix technique, that leads to a reverse-tunnel implant capable of providing network-level proxy access through a compromised host. This TerminalFix campaign uses fake CAPTCHA verification prompts to facilitate user-executed PowerShell commands. Beyond the initial lure, this campaign uses DLL sideloading through LockScreenContentServer.exe, steganographic payload delivery, and persistence mechanisms. It then performs extensive reconnaissance to identify reachable systems and key infrastructure. Organizations should investigate devices where users interacted with suspicious CAPTCHA verification prompts and look for unusual execution of LockScreenContentServer.exe, hidden ProgramData folders, and outbound connections associated with the activity. Additional guidance and technical analysis will be published soon by Microsoft Security Research.