Global EditionEnglish
Wed, 23 Sept, 2026Updated 05:13 pm IST
Breaking
Technology

Microsoft Warns of Fake CAPTCHA Malware

A new campaign called TerminalFix tricks Windows users into running malicious commands, potentially leading to data theft and ransomware installation

Microsoft Warns of Fake CAPTCHA Malware
Photo: Lee Campbell / Pexels

Microsoft has identified a new malware campaign called TerminalFix that uses fake CAPTCHA prompts to trick Windows users into running malicious commands. The campaign is a variation of the ClickFix attacks that have become increasingly common among business users.

The fake CAPTCHA pages impersonate trusted services like Cloudflare, instructing users to open PowerShell or Command Prompt and paste in a command. This allows attackers to execute longer, multi-line scripts, increasing the likelihood of successful infection.

The TerminalFix campaign can lead to persistent proxy access, data theft, and ransomware installation. After a user runs the command, the attacker can begin a multi-stage intrusion, giving them access to other parts of a company's network.

Microsoft recommends several mitigation measures, including restricting access to PowerShell and the Windows Run dialog, monitoring systems for signs of DLL sideloading, blocking Flash plugins, and enabling cloud-delivered protection in Microsoft Defender Antivirus.

The TerminalFix campaign relies on social engineering rather than a hidden software exploit, highlighting the importance of user awareness and caution when encountering unfamiliar prompts. A legitimate CAPTCHA service does not require users to run system commands to prove they are human.

## What happens next Microsoft Threat Intelligence has published guidance for organizations to mitigate the TerminalFix campaign. The company is also reviewing its Defender's URL reputation classification process after a recent incident where Microsoft Defender for Office 365 Safe Links blocked access to Google search links due to a misclassification issue.

The issue was resolved on September 2, 2026, at 10:17 UTC, but it highlights the ongoing challenges in balancing security with usability. As malware campaigns continue to evolve, it is essential for users and organizations to stay vigilant and take proactive measures to protect themselves against these types of threats.

## Why it matters The TerminalFix campaign is a reminder that familiar browser prompts can now bypass technical safeguards by convincing users to execute the attacker's code themselves. This highlights a broader security problem, where social engineering tactics can be just as effective as technical exploits in compromising systems. As a result, it is crucial for organizations to prioritize user education and awareness, as well as implement robust security measures to prevent and detect these types of attacks.

Sources

Topics

Send a tip