A page that asks you to "confirm that you're human" by opening PowerShell and pasting a command isn't a verification—it's a widespread scam called ClickFix.
Microsoft has recently documented a new variant of the attack, called TerminalFix. A compromised website displays a fake Cloudflare CAPTCHA, then guides the visitor, step by step, to copy a command and paste it into Windows Terminal or PowerShell. The command silently downloads a “backdoor” that gives the attacker access to the company’s internal network—from which they can proceed to steal data, disable security measures, and deploy ransomware.
What makes this attack so dangerous is that it doesn't exploit any software vulnerabilities. There is no "patch" to install, because the only thing being exploited is the user's trust. For this reason, the ClickFix technique was the most common method of gaining access to companies last year: 47% of the attacks observed by Microsoft.
For a small business, security is simple and depends more on people than on technology. Here’s a rule every employee should know: a legitimate “I’m human” verification can be completed with a single click or checkbox and never asks you to open Terminal, PowerShell, or the Run window (Win+R) and paste a command. If a page asks you to do this, close it immediately.
From a technical standpoint, risk-mitigation measures are within the reach of any IT provider:
- Restricting command execution for regular users (AppLocker or Group Policy);
- Blocking or auditing the Run dialog (Win+R) where it is not necessary;
- Enable PowerShell command logging so you can detect suspicious commands;
- providing regular training to the team on how to recognize this type of scam.
Sources:
- The Hacker News | https://thehackernews.com/2026/08/terminalfix-uses-fake-cloudflare.html
- Microsoft Security Blog | https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/
This article was generated with AI assistance.