SOC Prime Bias: High

05 Oct 2026 17:14 UTC

TerminalFix Campaign Enables Network Pivoting Through Compromised Hosts

Author Photo
SOC Prime Team linkedin icon Follow
TerminalFix Campaign Enables Network Pivoting Through Compromised Hosts
shield icon

Detection stack

  • AIDR
  • Alert
  • ETL
  • Query

Summary

TerminalFix is a variant of the ClickFix technique in which attackers use fake Cloudflare verification prompts to manipulate users into executing malicious PowerShell commands. The attack combines DLL sideloading, steganography-based payload delivery, and a WebSocket-based reverse tunnel. This enables the compromised workstation to function as a network pivot for additional reconnaissance and potential ransomware deployment.

Investigation

The investigation examined the attack lifecycle from the initial web-based lure through post-exploitation activity. Analysts identified LockScreenContentServer.exe being abused for DLL sideloading and PNG files being used for steganographic payload delivery. The campaign was further associated with Vice Spider based on German media reporting and advisories published by the BSI.

Mitigation

Defenders should monitor for suspicious browser-based iframes followed by PowerShell or Windows Terminal execution. Organizations should detect unusual DLL loading behavior, particularly legitimate binaries loading DLLs from unexpected locations such as C:\ProgramData. Restricting PowerShell execution policies and monitoring for unauthorized scheduled tasks and registry Run key modifications can further reduce attack exposure.

Response

When TerminalFix activity is detected, isolate the affected workstation to prevent it from operating as a network pivot. Analyze network traffic for external WebSocket connections to unknown domains and internal reconnaissance activity such as LDAP queries. Review endpoint telemetry for unauthorized Python script execution and the use of tools including Impacket and Certipy.

Attack Flow

We are still updating this part.

Detections

Suspicious Operations on NoWarningNoElevationOnInstall Registry Key (via registry_event)

SOC Prime Team
05 Oct 2026

Possible Persistence Points [ASEPs – Software/NTUSER Hive] (via registry_event)

SOC Prime Team
05 Oct 2026

Possible Impacket Command Line Patterns (via cmdline)

SOC Prime Team
05 Oct 2026

Possible Remote Code Execution using Impacket (via cmdline)

SOC Prime Team
05 Oct 2026

Python Execution from Suspicious Folders (via cmdline)

SOC Prime Team
05 Oct 2026

Possible Admin Account or Group Enumeration (via cmdline)

SOC Prime Team
05 Oct 2026

Suspicious Domain Trusts Discovery (via cmdline)

SOC Prime Team
05 Oct 2026

Possible Lateral Movement via PsExec or Similar (via system)

SOC Prime Team
05 Oct 2026

Possible Lateral Movement via PsExec or Similar (via audit)

SOC Prime Team
05 Oct 2026

Possible PsExec Usage (via audit)

SOC Prime Team
05 Oct 2026

IOCs (SourceIP) to detect: TerminalFix: When a Workstation Becomes a Network Pivot

SOC Prime AI Rules
05 Oct 2026

IOCs (DestinationIP) to detect: TerminalFix: When a Workstation Becomes a Network Pivot

SOC Prime AI Rules
05 Oct 2026

TerminalFix Network Pivot Detection [Windows Network Connection]

SOC Prime AI Rules
05 Oct 2026

Detect TerminalFix Malicious Execution [Windows Process Creation]

SOC Prime AI Rules
05 Oct 2026

Detection of Malicious PowerShell Commands for ZIP and PNG Retrieval [Windows Powershell]

SOC Prime AI Rules
05 Oct 2026

Simulation Execution

  • Attack Narrative & Commands: The adversary has gained initial access and is attempting to establish a persistent C2 channel to pivot through the workstation. To blend in with standard web traffic, they utilize the WebSocket protocol. The attacker executes a PowerShell script that initiates a connection to gitnow.dev. This mimics the TerminalFix behavior where the workstation acts as a relay. The goal is to trigger the selection_domain and selection_connection criteria of the detection rule.

  • Regression Test Script:

      # Simulation of TerminalFix C2 WebSocket connection
      # Target Domain: gitnow.dev
    
      $targetDomain = "gitnow.dev"
      $uri = "wss://$targetDomain/path/to/c2"
    
      Write-Host "Simulating TerminalFix C2 connection to $targetDomain..."
    
      $ws = New-Object System.Net.WebSockets.ClientWebSocket
      $ct = New-Object System.Threading.CancellationTokenSource
    
      try {
          # Attempting the connection to generate Network Connection telemetry
          $connectTask = $ws.ConnectAsync($uri, $ct.Token)
    
          # We use a timeout because the domain likely doesn't exist/won't respond
          if ($connectTask.Wait(10000)) {
              Write-Host "Successfully connected to $targetDomain"
              $ws.CloseAsync([System.Net.WebSockets.WebSocketCloseStatus]::NormalClosure, "Closing", $ct.Token).Wait()
          }
      } catch {
          Write-Host "Connection attempted. Telemetry should be generated in Sysmon/EDR logs."
          Write-Host "Error Detail: $($_.Exception.Message)"
      } finally {
          $ws.Dispose()
      }
  • Cleanup Commands:

      # No persistence or files were created in this specific simulation script.
      # If any temporary files were used, they should be removed here.
      Write-Host "Simulation cleanup complete. No artifacts left by this script."