TerminalFix가 Cloudflare CAPTCHA를 이용해 악성 명령어를 실행하도록 유도하는 기법을 설명합니다.
Microsoft는 TerminalFix라는 새로운 ClickFix 변종에 대한 세부 정보를 공개했습니다. 이 악성코드는 사용자를 유인하여 Windows Terminal이나 PowerShell에서 악성 명령을 실행하게 만듭니다. 전통적인 ClickFix 캠페인은 사용자를 Windows 실행 대화 상자로 유도하는 반면, TerminalFix 캠페인은 Windows Terminal이나 PowerShell로 유도하여 복잡한 명령어 실행 가능성을 높입니다.
TerminalFix uses fake Cloudflare CAPTCHAs to trick users into running malicious commands.
Microsoft has disclosed details of a new ClickFix variant, called TerminalFix. This malware tricks users into running malicious commands in Windows Terminal or PowerShell. While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns replace this with Windows Terminal or PowerShell, increasing the likelihood of executing complex commands.