Daily Security Intel

Archives
Log in
Subscribe
August 31, 2026

[SecurityIntel] 31 Aug | TerminalFix ClickFix attacks deploy reverse-tunnel backdoors.

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Monday, August 31, 2026

INTEL CONFIDENCE  70%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

TerminalFix ClickFix attacks deploy reverse-tunnel backdoors.

CRITICAL

5

C2 IPs

0

OTX IOCs

6

ARTICLES

■ ANALYST TLDR

Today's threat landscape highlights critical social engineering and session hijacking campaigns, notably the "TerminalFix" ClickFix variant deploying reverse-tunnel backdoors via fake Cloudflare CAPTCHAs. Additionally, infostealer malware is actively targeting Anthropic Claude sessions to drain API usage, while malicious Chrome and Edge extensions are stealing cryptocurrency and browser data. On the data breach front, the FulcrumSec group claims to have exfiltrated 86 GB of sensitive traveller and booking data from Manchester Airports Group.

■ CRITICAL STORIES

HIGH#1

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

Attackers are leveraging a new ClickFix variant named TerminalFix, which tricks users into executing malicious PowerShell commands via fake Cloudflare CAPTCHAs to establish reverse tunnels.

HIGH#2

Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

Infostealer malware on user PCs is stealing active Claude login session tokens, allowing threat actors to hijack accounts, access sensitive prompts, and drain API/usage limits.

HIGH#3

FulcrumSec claims Manchester Airports hack, theft of 86 GB of data

Threat group FulcrumSec has claimed a breach of Manchester Airports Group, leaking 86 GB of data containing sensitive customer, travel, and booking details.

INFO#4

Chrome Web Store extensions caught stealing crypto, browser data

Multiple malicious extensions in the Chrome Web Store and Microsoft Edge Add-ons catalog have been found deploying malware frameworks to steal browser history and crypto assets.

■ CVEs IDENTIFIED

[CVE-TBD]

Anthropic Claude — Session hijacking leading to unauthorized account access and usage draining via infostealer malware.

High

[CVE-TBD]

Google Chrome & Microsoft Edge Extensions — Malicious extension framework execution leading to cryptocurrency and browser data theft.

High

[CVE-TBD]

Microsoft Windows Terminal / PowerShell — TerminalFix social engineering leading to arbitrary command execution and reverse-tunnel backdoor deployment.

High

■ THREAT ACTORS

FulcrumSec

Cybercrime / Extortion

Exfiltrated and leaked 86 GB of customer and booking data from Manchester Airports Group.

■ ATT&CK TTPs

T1539
Steal Web Session Cookie | Infostealers stealing active Claude login sessions from browsers.
T1176
Browser Extensions | Malicious Chrome and Edge extensions used to deploy data-stealing modules.
T1204.002
User Execution: Malicious File/Command | ClickFix/TerminalFix tricking users into pasting malicious commands into Windows Terminal.
T1071.001
Application Layer Protocol: Web Protocols | TerminalFix establishing reverse-tunnel backdoors to C2.
T1567.002
Exfiltration to Cloud Storage | FulcrumSec exfiltrating 86 GB of traveller data.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Google Chrome & Microsoft Edge — Audit and restrict extensions to prevent active credential and crypto theft — BleepingComputer

[P1 PATCH NOW]≤24h

Microsoft Windows Terminal / PowerShell — Restrict execution policies to block TerminalFix reverse-tunnel backdoors — The Hacker News

[P3 PATCH NOW]≤1 week

VirusTotal YARA-X — Update to version 1.20.0 to fix bugs and improve detection capabilities — SANS

■ RECOMMENDED ACTIONS TODAY

1[P1] Implement strict session lifetime limits and concurrent session controls for Anthropic Claude and other enterprise SaaS portals to mitigate infostealer session hijacking [CVE-TBD].
2[P1] Deploy administrative policies (GPO/Intune) to restrict the installation of unapproved Google Chrome and Microsoft Edge extensions, and audit existing extensions [CVE-TBD].
3[P2] Educate users against pasting untrusted commands into Windows Terminal or PowerShell, specifically targeting fake Cloudflare CAPTCHA ("ClickFix") prompts [CVE-TBD].
4[P2] Update YARA-X installations to version 1.20.0 to leverage the latest bugfixes and performance improvements for threat detection.
5[P3] Manchester Airports Group customers should monitor for phishing and identity theft attempts following the 86 GB data leak by FulcrumSec.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 01 Sep | Chinese Fire Ant Hackers Hijack Cisco Routers Older → [SecurityIntel] 30 Aug | Critical WordPress Flaws and TerminalFix Campaigns Escalate
Powered by Buttondown, the easiest way to start and grow your newsletter.