Attackers turn fake Cloudflare checks into network tunnels

Microsoft detailed the TerminalFix campaign, which uses a compromised website to show a fake Cloudflare verification prompt that tells visitors to paste a PowerShell command. Microsoft says the following stages can establish persistence, conduct domain reconnaissance, and deploy an encrypted reverse tunnel.
This is not a normal browser warning that an admin can solve by training people to spot an odd attachment. The initial instruction looks like a familiar verification step, but it asks the user to turn a clipboard action into local code execution. Small IT teams need a response path that joins user reports with endpoint and identity evidence. Microsoft’s write-up includes the attack chain, indicators, detection detail, and hunting guidance, so the practical value is in using it to tune that path rather than treating it as security news to read and forget.
Analysis
Send your security owner Microsoft’s TerminalFix indicators and confirm that help-desk staff know to escalate any report of a website asking users to paste a verification command.
Source note
Pulse published by Collab365 Spaces, reviewed by Helen Jones on . Cite as "Fake Cloudflare checks can become an admin incident", Collab365 Spaces.