SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefMonday, August 31, 2026 INTEL CONFIDENCE 70% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY TerminalFix ClickFix attacks deploy reverse-tunnel backdoors. | CRITICAL |
|
5 C2 IPs | 0 OTX IOCs | 6 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape highlights critical social engineering and session hijacking campaigns, notably the "TerminalFix" ClickFix variant deploying reverse-tunnel backdoors via fake Cloudflare CAPTCHAs. Additionally, infostealer malware is actively targeting Anthropic Claude sessions to drain API usage, while malicious Chrome and Edge extensions are stealing cryptocurrency and browser data. On the data breach front, the FulcrumSec group claims to have exfiltrated 86 GB of sensitive traveller and booking data from Manchester Airports Group. |
|
■ CRITICAL STORIES TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor Attackers are leveraging a new ClickFix variant named TerminalFix, which tricks users into executing malicious PowerShell commands via fake Cloudflare CAPTCHAs to establish reverse tunnels. |
Anthropic warns infostealer malware is hijacking Claude sessions to drain usage Infostealer malware on user PCs is stealing active Claude login session tokens, allowing threat actors to hijack accounts, access sensitive prompts, and drain API/usage limits. |
FulcrumSec claims Manchester Airports hack, theft of 86 GB of data Threat group FulcrumSec has claimed a breach of Manchester Airports Group, leaking 86 GB of data containing sensitive customer, travel, and booking details. |
Chrome Web Store extensions caught stealing crypto, browser data Multiple malicious extensions in the Chrome Web Store and Microsoft Edge Add-ons catalog have been found deploying malware frameworks to steal browser history and crypto assets. |
|
■ CVEs IDENTIFIED [CVE-TBD] Anthropic Claude — Session hijacking leading to unauthorized account access and usage draining via infostealer malware. |
[CVE-TBD] Google Chrome & Microsoft Edge Extensions — Malicious extension framework execution leading to cryptocurrency and browser data theft. |
[CVE-TBD] Microsoft Windows Terminal / PowerShell — TerminalFix social engineering leading to arbitrary command execution and reverse-tunnel backdoor deployment. |
|
■ THREAT ACTORS FulcrumSec | Cybercrime / Extortion |
Exfiltrated and leaked 86 GB of customer and booking data from Manchester Airports Group. |
|
|
|
■ ATT&CK TTPs | T1539 | | Steal Web Session Cookie | Infostealers stealing active Claude login sessions from browsers. |
| T1176 | | Browser Extensions | Malicious Chrome and Edge extensions used to deploy data-stealing modules. |
| T1204.002 | | User Execution: Malicious File/Command | ClickFix/TerminalFix tricking users into pasting malicious commands into Windows Terminal. |
| T1071.001 | | Application Layer Protocol: Web Protocols | TerminalFix establishing reverse-tunnel backdoors to C2. |
| T1567.002 | | Exfiltration to Cloud Storage | FulcrumSec exfiltrating 86 GB of traveller data. |
|
■ PATCH PRIORITY Google Chrome & Microsoft Edge — Audit and restrict extensions to prevent active credential and crypto theft — BleepingComputer |
Microsoft Windows Terminal / PowerShell — Restrict execution policies to block TerminalFix reverse-tunnel backdoors — The Hacker News |
VirusTotal YARA-X — Update to version 1.20.0 to fix bugs and improve detection capabilities — SANS |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Implement strict session lifetime limits and concurrent session controls for Anthropic Claude and other enterprise SaaS portals to mitigate infostealer session hijacking [CVE-TBD]. |
| 2 | [P1] Deploy administrative policies (GPO/Intune) to restrict the installation of unapproved Google Chrome and Microsoft Edge extensions, and audit existing extensions [CVE-TBD]. |
| 3 | [P2] Educate users against pasting untrusted commands into Windows Terminal or PowerShell, specifically targeting fake Cloudflare CAPTCHA ("ClickFix") prompts [CVE-TBD]. |
| 4 | [P2] Update YARA-X installations to version 1.20.0 to leverage the latest bugfixes and performance improvements for threat detection. |
| 5 | [P3] Manchester Airports Group customers should monitor for phishing and identity theft attempts following the 86 GB data leak by FulcrumSec. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |