Skip to main content

ExtraHop® Closes Enterprise Data Center Blind Spots with new 400 Gbps sensor

Search
  • Solutionschevron right
  • Industrieschevron right
  • Platformchevron right
  • Resourceschevron right
  • Customerschevron right
  • Companychevron right

TerminalFix: When a Workstation Becomes a Network Pivot

Share blog icon

Back to top

Back to top

October 1, 2026

Anatomy of an Attack:

TerminalFix: When a Workstation Becomes a Network Pivot

According to an August 28 report from Microsoft, TerminalFix is a variant of the ClickFix technique. Similar to typical ClickFix tactics, the attack starts by tricking targets with a fake Cloudflare human verification check. Victims are lured into executing a copied command within PowerShell or Windows Terminal, unlike conventional ClickFix schemes that utilize the Windows Run prompt. The execution triggers a multi-stage intrusion sequence featuring DLL sideloading, hidden payloads, persistent access, Active Directory (AD) discovery, and a reverse C2 tunnel.

German incident reporting illustrates the potential consequences. DIESEC’s account of a September 4 advisory reported that Germany’s Federal Office for Information Security (BSI) had been notified of a German state institution compromise matching the TerminalFix pattern in August. The actors attempted to install ransomware and exfiltrate data for double extortion. Separately, German media (heise.de) identified TerminalFix as an initial access vector into the Berlin Senate’s network and linked the malware to Vice Spider. BSI’s advisory did not itself name Berlin or Vice Spider.

This attack chain produces a visible sequence of anomalous network behaviors. A standard user endpoint downloading payloads, performing network reconnaissance, and establishing an external relay channel is highly suspicious. This entire sequence unfolds across the network and ExtraHop RevealX can automatically detect the deviations in real time. RevealX passively exposes this activity by baselining normal device behavior, flagging the sudden AD queries and external tunnel traffic even when the initial payload is concealed. Correlating internal and external traffic gives incident responders the context needed to isolate the threat.

The TerminalFix Attack Lifecycle

Phase 1: Fake Cloudflare Verification Leads to PowerShell Execution

The actors use compromised websites [T1189] to deliver a fake Cloudflare verification overlay. The lure instructs targets to copy a command and paste a command [T1204.004] into Windows Terminal or PowerShell. In contrast to traditional ClickFix campaigns that rely on single-line commands executed through the Windows Run dialog, these applications support multiline, extended commands. Once executed, PowerShell [T1059.001] fetches a ZIP archive from adversary infrastructure and extracts its contents to C:\ProgramData. A batch script then triggers the execution of the next stage, all while deceptive Cloudflare verification screens remain displayed to the user.

Hunt for the behavior: Third-party iframes embedded on compromised websites frequently serve ClickFix overlays. To investigate, examine browser logs for suspicious verification pages, cross-referencing them with endpoint activity for concurrent PowerShell or Terminal execution. Follow any resulting ZIP archive downloads back to their origin, mapping out all created files and initiated processes.

Phase 2: DLL Sideloading and PNG Steganography Payloads

The downloaded ZIP file pairs LockScreenContentServer[.]exe, a legitimate Microsoft-signed Windows binary, and a malicious dui70[.]dll. This DLL masquerades as “Windows DirectUI Engine”, which LockScreenContentServer[.]exe is dependent on. When the executable loads the DLL file [T1574.001], the malicious code is run inside the trusted LockScreenContentServer process.

The attack chain then uses PowerShell to retrieve PNG files via HTTP POST requests from actor-controlled infrastructure. Binary payloads are hidden in the PNG files using steganography [T1027.003]. The script reconstructs the binary payloads from the PNG file’s pixel data, with one providing the executable and the other two supplying portions of a DLL.

Hunt for the behavior: Look for LockScreenContentServer[.]exe loading dui70[.]dll from an unexpected location. On the same workstation, check for PowerShell retrieving PNG files through HTTP POST requests and then writing executable or DLL files to disk.

Phase 3. Registry Run Key and Scheduled Task Persistence

For persistence, a Registry Run entry [T1547.001] is added and an hourly scheduled task [T1053.005] relaunches the payload. These mechanisms reduce its dependence on the original browser session.

Hunt for the behavior: Inspect Registry Run entries and hourly scheduled tasks for commands that relaunch the payload. Check whether suspicious external connections return after logon or scheduled executions.

Phase 4. Active Directory Reconnaissance and Privileged Account Discovery

The script enumerates domain trusts and Domain Admins, harvests AD user descriptions, queries Windows Server computer objects, and pings servers. The reported commands included nltest /domain_trusts and net group "domain admins" /domain.

The commands identify domain relationships, privileged accounts, and potential internal targets. Domain trust discovery [T1482] describes relationships between domains, while domain admins identifies privileged accounts [T1087.002]. Querying of computer objects [T1018] and pinging servers reveal which hosts are reachable from the workstation.

Hunt for the behavior: Identify workstations that begin querying domain trusts and AD computer objects, enumerating privileged groups, and probing servers. Check whether the workstation normally performs these tasks and whether the activity matches an approved administrative tool or task.

Phase 5. Reverse Tunnel and WebSocket Command and Control

After reconnaissance, a PowerShell loop monitors a local command file and executes instructions. The results are stored in a separate file. The chain then launches pythonw.exe to run client.py, a custom tunnel client. The client connects to an actor-controlled domain gitnow[.]dev:443 and upgrades the connection to WebSocket at /tunnel within TLS [T1572].

This is where the workstation can turn into a relay. The actor can send traffic through the external channel and have the infected workstation open connections to internal destinations.

Hunt for the behavior: Investigate workstations that maintain unfamiliar external connections while opening new connections to internal systems. Identify the internal destinations, then use endpoint records to check for pythonw.exe running client.py. Establish whether the workstation is authorized to provide remote access and whether the observed connections fit that purpose.

Phase 6. Attempted Ransomware and Data Theft

German incident reporting describes what followed a TerminalFix compromise. On September 8, DIESEC reported that BSI’s September 4 advisory described attackers attempting to install ransomware and exfiltrate data for double extortion at a German state institution.

Hunt for the behavior: Review ransomware and unusual file-activity alerts involving the compromised workstation and any servers it contacted. Look for file-server evidence to determine whether files were encrypted. Check whether approved compression or encryption jobs explain the activity.

Detect the Behavior: MITRE ATT&CK to ExtraHop Mapping

Loading table...

TerminalFix IOCs and Additional Potential Infrastructure

Loading table...

Analysis of the gitnow[.]dev domain

On September 22, 2026, according to threat intelligence data, the actor-controlled domain gitnow[.]dev resolved to 92.118.126[.]201 hosted by BlueVPS OU. While this server has not been assessed whether or not it is directly connected to the threat actors behind the TerminalFix campaign, it offers valuable intelligence for security personnel.

The operator used ProxyChains to open a Bash shell configured to send supported network connections through a proxy. They used curl to test the SOCKS proxy at 92.118.126[.]201:58421 and check its outward-facing IP address. They then opened the ProxyChains configuration in nano for editing and launched another shell, presumably to use the updated settings. Finally, they used Impacket’s ntlmrelayx through ProxyChains to attempt an authentication relay attack against the internal certificate service on a targeted domain controller. The goal was to obtain a certificate that would let them impersonate a domain controller, but the operator’s success is unknown.

As of this writing, the IP address contained Active Directory tooling, shell history, Kerberos ticket caches, certificate-authority enumeration outputs, and relay runtime logs. In examining the bash history, it appeared that the operator attempted to exploit multiple organizations and may have been successful in obtaining user credentials. The host included attacker tooling such as:

  • CertiGhost
  • Certipy
  • Impacket
  • Krbrelayx
  • noPac
  • PetitPotam
  • PrintNightmare
Loading table...

For a detailed look at how an attacker uses some of these tools, read ExtraHop’s PetitPotam: Expanding NTLM Relay Attacks, Breaking Through Encrypted East-West Traffic and Threading the Needle: Detecting AD CS Abuse Through Decryption.

Analysis of the bestsocialmedianewspapper[.]com and offlineupdater[.]com domains

There was no further intelligence regarding the actor’s two other domains. As of September 22, 2026, both domains were hosted on BlueVPS OU IPs and registered on August 12th.

Domain: bestsocialmedianewspapper[.]com
IP Address: 45.66.249[.]112
Date registered: 2026-08-12T17:17:11Z

Domain: offlineupdater[.]com
IP Address: 92.118.126[.]225
Date registered: 2026-08-12T15:32:54Z

Defensive Implications and Network Detection Capabilities

TerminalFix changes the compromised workstation’s role. A device used for browsing becomes a source of directory discovery and potentially a route to internal services. That transition gives defenders a way to connect activity that might otherwise be reviewed separately: payload delivery, server enumeration, external communication, and new connections to internal peers.

Network visibility should cover both the workstation’s internet access and its paths to directory services and internal servers. The mapping table identifies ExtraHop detections relevant to the directory queries and server probing. Where directory traffic is encrypted or sealed, analysts must establish whether the operations required for detection are available. On the external path, connection metadata can help prioritize a suspicious channel, but confirming its purpose requires endpoint evidence or suitable content visibility.

Microsoft’s analysis documents persistent execution, domain reconnaissance, and a reverse tunnel capable of reaching internal services. Separate German incident reporting describes a compromise matching the TerminalFix pattern in which actors attempted ransomware deployment and data theft for double extortion. Those findings illustrate the potential consequences of the access Microsoft documented. The risk extends beyond the infected workstation to the systems and data accessible from it.

Key Takeaways

  • TerminalFix uses a fake verification prompt to turn a user’s pasted command into staged payload delivery and persistent execution.
  • Directory queries and server probing expose the compromised workstation’s effort to map the internal environment.
  • The reverse tunnel can relay access to reachable services. Check which internal systems the workstation contacted while the external connection was active.
blog image
Blog author
Angela Wilson

Senior Cyber Threat Intelligence Analyst

Angela Wilson is a Senior Cyber Threat Intelligence Analyst with over a decade of experience in the cybersecurity industry. She focuses on transforming complex threat data into strategic intelligence that enhances organizational resilience and informs proactive defense.

Share
LinkedIn logoX logoFacebook logo

Explore related articles

Experience RevealX NDR for Yourself

Schedule a demo