Cortex XDR
TerminalFix campaign deploys a reverse tunnel through multistage intrusion.
markdown
> Make sure you're comfortable with the results in your own environment before using this more widely.
# TerminalFix Campaign Hunting with XQL
## Scenario Overview
[Microsoft Threat Intelligence](https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/) has observed a **TerminalFix** campaign—a variant of *ClickFix*—targeting organizations across multiple industries.
Unlike traditional ClickFix campaigns that direct victims to the Windows Run dialog (`Win + R`), TerminalFix tricks users into pasting commands into **Windows Terminal** or **PowerShell**, increasing the likelihood that complex, multi-line scripts execute successfully.
> **Attack Vector:** Compromised websites display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell script.
---
## Attack Chain Breakdown
### 1. Initial Execution & Sideloading
Once executed, the PowerShell script masquerades as a Cloudflare verification process to download a `.zip` archive containing:
* **Legitimate Binary:** `LockScreenContentServer.exe`
* **Malicious DLL:** `dui70.dll` (used for DLL sideloading)
### 2. Multi-Stage Payload Delivery & Persistence
The sideloaded DLL executes an elaborate second stage that includes:
* **Steganography:** Downloads secondary payloads hidden inside PNG images.
* **Dual Persistence:** Establishes persistence using both **Registry Run keys** and **Scheduled Tasks**.
### 3. Active Directory Reconnaissance
The script performs thorough domain reconnaissance, including:
* Domain trust enumeration & Domain Admin discovery
* Active Directory user description harvesting
* Targeted server ping sweeps
### 4. Command & Control (C2) Implant
Deploys a Python-based reverse-tunnel C2 implant that tunnels arbitrary TCP traffic back through an encrypted WebSocket channel to attacker infrastructure—giving the attacker persistent, network-level proxy access.
xql
// Make sure you're comfortable with the results in your own environment before using this more widely.
// This query detects process creation events where PowerShell launches cmd.exe to execute a payload from \ProgramData\.
dataset = xdr_data
| filter event_type = ENUM.PROCESS and event_sub_type = ENUM.PROCESS_START
| filter actor_process_image_name = "powershell.exe" and action_process_image_name = "cmd.exe"
| filter action_process_image_command_line contains "\ProgramData\"
and action_process_image_command_line contains "1.bat"
and action_process_image_command_line contains "LockScreenContentServer.exe"
| fields _time, agent_hostname, actor_effective_username, actor_process_image_name
xql
// Make sure you're comfortable with the results in your own environment before using this more widely.
// This query identifies cases where LockScreenContentServer.exe loads dui70.dll from its own running directory (a classic sideloading indicator) while excluding standard, trusted Windows and Program Files directories.
// We use regular expression extraction (regextract) to strip the file name and isolate the directory paths for comparison.
dataset = xdr_data
| filter action_module_path contains "dui70.dll" and actor_process_image_name = "LockScreenContentServer.exe"
| alter path = arrayindex(regextract(action_module_path, "^(.*\\)[^\\]+$"), 0),
proc_dir = arrayindex(regextract(actor_process_image_path, "^(.*\\)[^\\]+$"), 0)
| filter path = proc_dir
| filter path not contains "windows\system32"
and path not contains "windows\syswow64"
and path not contains "\winsxs\"
and path not contains "program files"
and path not contains "windows defender"
and path not contains "microsoft security client"
and path not contains "program files\windows"
and path not contains "program files\microsoft"
and path not contains "programdata\microsoft"
and path not contains "microsoft\windows"
and path not contains "amd64_windows-defender-service"
and path not contains "microsoft defender for endpoint"
| fields _time, agent_hostname, actor_effective_username, actor_process_image_name
xql
// Make sure you're comfortable with the results in your own environment before using this more widely.
// This query hunts for Python processes launching the specific client.py reverse tunnel script with its characteristic command-line flags.
dataset = xdr_data
| filter event_type = ENUM.PROCESS and event_sub_type = ENUM.PROCESS_START
| filter action_process_image_name in ("pythonw.exe", "python.exe")
| filter action_process_image_command_line contains "client.py"
and action_process_image_command_line contains "--server"
and action_process_image_command_line contains "--uuid"
and action_process_image_command_line contains "cert.pem"
and action_process_image_command_line contains "gitnow.dev"
| fields _time, agent_hostname, actor_effective_username, action_process_image_name
xql
// Make sure you're comfortable with the results in your own environment before using this more widely.
// This query flags outbound network connections made to any of the specified malicious C2 domains using XQL's efficient wildcard-supporting list operator.
dataset = xdr_data
| filter event_type = ENUM.NETWORK
| filter action_external_hostname in ("*gitnow.dev*", "*bestsocialmedianewspapper.com*", "*offlineupdater.com*")
| fields _time, agent_hostname, action_external_hostname, action_remote_port, actor_process_image_name