TerminalFix Campaign Enables Network Pivoting Through Compromised Hosts
Detection stack
- AIDR
- Alert
- ETL
- Query
Summary
TerminalFix is a variant of the ClickFix technique in which attackers use fake Cloudflare verification prompts to manipulate users into executing malicious PowerShell commands. The attack combines DLL sideloading, steganography-based payload delivery, and a WebSocket-based reverse tunnel. This enables the compromised workstation to function as a network pivot for additional reconnaissance and potential ransomware deployment.
Investigation
The investigation examined the attack lifecycle from the initial web-based lure through post-exploitation activity. Analysts identified LockScreenContentServer.exe being abused for DLL sideloading and PNG files being used for steganographic payload delivery. The campaign was further associated with Vice Spider based on German media reporting and advisories published by the BSI.
Mitigation
Defenders should monitor for suspicious browser-based iframes followed by PowerShell or Windows Terminal execution. Organizations should detect unusual DLL loading behavior, particularly legitimate binaries loading DLLs from unexpected locations such as C:\ProgramData. Restricting PowerShell execution policies and monitoring for unauthorized scheduled tasks and registry Run key modifications can further reduce attack exposure.
Response
When TerminalFix activity is detected, isolate the affected workstation to prevent it from operating as a network pivot. Analyze network traffic for external WebSocket connections to unknown domains and internal reconnaissance activity such as LDAP queries. Review endpoint telemetry for unauthorized Python script execution and the use of tools including Impacket and Certipy.
Attack Flow
We are still updating this part.
Detections
Suspicious Operations on NoWarningNoElevationOnInstall Registry Key (via registry_event)
Possible Persistence Points [ASEPs – Software/NTUSER Hive] (via registry_event)
Possible Impacket Command Line Patterns (via cmdline)
Possible Remote Code Execution using Impacket (via cmdline)
Python Execution from Suspicious Folders (via cmdline)
Possible Admin Account or Group Enumeration (via cmdline)
Suspicious Domain Trusts Discovery (via cmdline)
Possible Lateral Movement via PsExec or Similar (via system)
Possible Lateral Movement via PsExec or Similar (via audit)
Possible PsExec Usage (via audit)
IOCs (SourceIP) to detect: TerminalFix: When a Workstation Becomes a Network Pivot
IOCs (DestinationIP) to detect: TerminalFix: When a Workstation Becomes a Network Pivot
TerminalFix Network Pivot Detection [Windows Network Connection]
Detect TerminalFix Malicious Execution [Windows Process Creation]
Detection of Malicious PowerShell Commands for ZIP and PNG Retrieval [Windows Powershell]
Simulation Execution
-
Attack Narrative & Commands: The adversary has gained initial access and is attempting to establish a persistent C2 channel to pivot through the workstation. To blend in with standard web traffic, they utilize the WebSocket protocol. The attacker executes a PowerShell script that initiates a connection to
gitnow.dev. This mimics the TerminalFix behavior where the workstation acts as a relay. The goal is to trigger theselection_domainandselection_connectioncriteria of the detection rule. -
Regression Test Script:
# Simulation of TerminalFix C2 WebSocket connection # Target Domain: gitnow.dev $targetDomain = "gitnow.dev" $uri = "wss://$targetDomain/path/to/c2" Write-Host "Simulating TerminalFix C2 connection to $targetDomain..." $ws = New-Object System.Net.WebSockets.ClientWebSocket $ct = New-Object System.Threading.CancellationTokenSource try { # Attempting the connection to generate Network Connection telemetry $connectTask = $ws.ConnectAsync($uri, $ct.Token) # We use a timeout because the domain likely doesn't exist/won't respond if ($connectTask.Wait(10000)) { Write-Host "Successfully connected to $targetDomain" $ws.CloseAsync([System.Net.WebSockets.WebSocketCloseStatus]::NormalClosure, "Closing", $ct.Token).Wait() } } catch { Write-Host "Connection attempted. Telemetry should be generated in Sysmon/EDR logs." Write-Host "Error Detail: $($_.Exception.Message)" } finally { $ws.Dispose() } -
Cleanup Commands:
# No persistence or files were created in this specific simulation script. # If any temporary files were used, they should be removed here. Write-Host "Simulation cleanup complete. No artifacts left by this script."