TerminalFix Social Engineering Campaign Using Cloudflare Lures
The TerminalFix campaign uses social engineering to trick users into pasting malicious PowerShell commands under the guise of a Cloudflare verification process, leading to secondary payload execution.
The TerminalFix campaign is a sophisticated social engineering attack observed as of August 2026. Attackers leverage browser-based overlays that present fake Cloudflare verification prompts to users. These prompts instruct the victim to copy a snippet of text and paste it into Windows Terminal or PowerShell to complete a supposed security check. When executed, the PowerShell script block performs malicious actions, including downloading secondary payloads, extracting archives, and launching follow-on scripts or executables. This campaign demonstrates a reliance on user-assisted execution of malicious commands, bypassing initial browser-based defenses. Defenders must focus on visibility into PowerShell script block execution to detect the specific language patterns associated with these lures.
Attack Chain
- User encounters a malicious website posing as a security-gated portal, triggering a fake Cloudflare verification prompt.
- The website instructs the user to open Windows Terminal or PowerShell and paste a provided command snippet.
- The victim executes the PowerShell script, which is recorded via PowerShell Script Block Logging (Event ID 4104).
- The script outputs deceptive text to the console, such as "Cloudflare ID:" or "I am not a robot," to maintain the illusion of a legitimate security process.
- The PowerShell script initiates background tasks to retrieve remote payloads, typically involving download or web-request commands.
- The script extracts downloaded archives to a user-writable or temporary system directory.
- The script executes secondary malicious payloads, such as batch files, VBScripts, or unsigned executables, to establish persistence or facilitate further intrusion.
Impact
Successful exploitation leads to unauthorized code execution on the target host. This allows for the deployment of reverse tunnels, persistent backdoors, or additional malware stages, potentially compromising credentials and sensitive information on the affected Windows endpoints.
Recommendation
- Enable and collect PowerShell Script Block Logging (Event ID 4104) across all Windows endpoints to capture the full context of executed scripts.
- Deploy the provided Sigma rule to monitor for specific lure-related strings in PowerShell execution telemetry.
- Proactively hunt for instances where PowerShell processes originate from user-interactive activities following browser navigation events.
- Educate users that legitimate Cloudflare or security verification processes never require the manual execution of commands in a terminal.
- Implement strict controls on command-line execution and use EDR/EPP solutions to alert on the launch of unexpected executables or scripts in temporary directory paths.
Immediate actions
Deploy PowerShell Script Block Logging across the domain.
Threat Hunt
Search 4104 logs for common Cloudflare-related lure strings.
Mitigations
Configure GPO to enable PowerShell Script Block Logging.
Detection coverage 1
Potential TerminalFix Cloudflare Lure in PowerShell
highDetects PowerShell script blocks containing common Cloudflare lure text used in the TerminalFix campaign.
Detection queries are available on the platform. Get full rules →