Serving tech enthusiasts for over 25 years.

TechSpot means tech analysis and advice you can trust.

The takeaway: Microsoft has identified a new malware campaign that uses fake CAPTCHA prompts to trick Windows users into running malicious commands. The campaign, called TerminalFix, is a variation of the ClickFix attacks that have become increasingly common among business users. The campaign highlights a broader security problem: familiar browser prompts can now bypass technical safeguards by convincing users to execute the attacker's code themselves.

The pages impersonate Cloudflare and other trusted services. Instead of presenting a normal CAPTCHA challenge, they instruct users to open PowerShell or Command Prompt and paste in a command.

That is the main difference between TerminalFix and earlier ClickFix activity. ClickFix attacks often direct victims to the Windows Run dialog, where a command is used to install an information stealer. TerminalFix, by contrast, uses PowerShell or Command Prompt, making it easier for attackers to execute longer, multi-line scripts.