Tag

#powershell

6 stories taggedpowershell.

A Windows Terminal window open on a user's screen displaying a spoofed CAPTCHA popup above it, malicious command strings visible in the terminal ready to be pas
Threat Intelligence

TerminalFix: The Fake CAPTCHA That Opens a Back Door Into Company Networks

Microsoft has spotted a new twist on the ClickFix scam that pushes victims to paste attacker commands straight into Windows Terminal, ending with a hidden tunnel into the internal network.

4 min read
An FTP server welcome screen with disguised command instructions hidden within greeting text, with malicious payloads downloading to a Windows system in the bac
Threat Intelligence

Hackers Hide Malware Instructions in FTP Server Greetings

A quiet trick spotted by SOCRadar uses FTP welcome messages to smuggle commands onto Windows machines, dropping two new remote-control tools called E4del and PINHOLE.

3 min read
Illustration: a darkened office monitor displaying a generic fake CAPTCHA verification page reflected in a glass surface
Threat Intelligence

ClickFix: The Fake Error Pop-Up That Tricks You Into Hacking Yourself

A scam that launched in 2024 has grown into a thriving criminal marketplace. Researchers say standard antivirus tools are missing it almost entirely, and they have built a new detection method to fill the gap.

4 min read
Illustration: a dark server room with a single glowing monitor in the middle distance displaying faint blue Windows-
Threat Intelligence

Attacker Uses AI-Written PowerShell Script to Map a Company's Network

Researchers say an unknown intruder ran a script that looks machine-generated to catalogue users, computers and domain controllers inside a Windows network.

4 min read
Illustration: a laptop screen showing a generic blurred verification prompt with a checkbox, warm desk lamp light
Threat Intelligence

Fake CAPTCHA Pages Are Stealing From Mexican Bank Customers

Elastic Security Labs is tracking a fraud campaign, dubbed REF6045, that tricks people into pasting a malicious command from a bogus 'prove you're human' page.

3 min read
Illustration: a darkened office monitor displaying a generic fake CAPTCHA verification page reflected in a glass surface
Threat Intelligence

ClickFix Grows a Back Office: API-Served Payloads and a New AMSI Bypass

Researchers pulled roughly 3,000 live payloads from ClickFix infrastructure and found a polymorphic delivery pipeline built to defeat Windows script scanning.

3 min read
© 2026 Threat Vectr