Overview
- The Bundesamt für Sicherheit in der Informationstechnik (BSI) publicly reported in early September that attackers used fake Captchas, known as TerminalFix, to trick Berlin administration employees into pasting and executing clipboarded commands in Windows Terminal or PowerShell.
- When executed the command downloaded a ZIP that launched a loader called LoremIpsumLoader or AxolotLoader, which then fetched benign-looking PNG files that were reassembled into active malware to evade antivirus detection.
- After infection the intruders scanned Active Directory, servers and backup systems, created reverse tunnels and established persistence through registry entries, scheduled tasks and hidden files to retain long-term access.
- Microsoft warned about this click‑style Captcha trick at the end of August and the BSI findings corroborate that user-focused social engineering remains the primary entry vector for this campaign tied to the Rhysida ransomware group.
- Authorities advise closing the browser if a Captcha asks you to run keyboard shortcuts, rebuilding infected machines from external backups and resetting all credentials when compromise is confirmed to remove persistent backdoors.