Published Date:
TerminalFix, fake CAPTCHA, PowerShell: can your employees recognize an attack like this – and respond correctly?
When people think of a phishing simulation, they usually picture a suspicious email, a link, and a fake Microsoft login page. And they’re not wrong. But I believe that view has become a little too narrow.
The cyberattack on the Berlin administration is a pretty good example of why.
A TerminalFix attack was the way in. According to the German Federal Office for Information Security (BSI), the two affected Senate administrations — Urban Development, Building and Housing, and Mobility, Transport, Climate Protection and the Environment — were compromised through TerminalFix, a variant of ClickFix associated with the Rhysida group. If you want the hands-on version, we have already written about how to build a ClickFix simulation in Cyberdise.
Someone reached a manipulated website — plausibly through a phishing email, though a link shared in a forum or on social media does the job just as well. There, what looked like a perfectly normal Cloudflare CAPTCHA appeared.
Except this CAPTCHA wasn’t trying to determine whether the visitor was human. It was designed to make the human perform the critical step of the attack themselves.
A malicious PowerShell command was placed in the clipboard by the page itself, and the user was then walked through opening the Windows Terminal — Windows+X, then I — and pasting it in. While the fake CAPTCHA kept asking for further steps, the command quietly pulled down the first stage of the malware in the background.
The result was an infected system and, ultimately, the publication of around 1.44 million files on the darknet — roughly 5.7 terabytes, by the attackers’ own account — after Berlin refused to pay the ransom.
What I find interesting about this is that the decisive step did not require some exotic technical vulnerability. It required a human being to follow an instruction that looked plausible.
Maybe we are still training the phishing email too often — instead of training for the attack itself?
The manipulation is no longer necessarily contained in the message itself. It is embedded in the process.
“Verify you’re human.”
“Your document cannot be displayed.”
“Press Windows-X, then I, and paste this command.”
For many employees, this doesn’t immediately look like a cyberattack. It looks like IT. And most of us are not IT experts, so we tend to follow what “IT” tells us to do.
That is precisely why it is no longer enough to teach people how to recognize suspicious senders or links. They also need to learn to question unusual processes, instructions, and situations.
Yes, of course! ☺ Exactly these kinds of scenarios can be simulated with CYBERDISE.
With CYBERDISE, companies can create personalized phishing and spear-phishing simulations, recreate websites as realistic landing pages, and combine different attack scenarios within a single campaign. AI-based hyperpersonalization is also possible.
This means you can build ClickFix and TerminalFix scenarios, for example: an employee lands on a simulated website, sees a fake CAPTCHA or what appears to be an IT instruction, and has to decide how to respond — naturally, without any actual malicious code.
The simulation is realistic enough to observe exactly the behavior that matters when a real attack occurs.
CYBERDISE also supports QR-code attack simulations. And with the Omnichannel Add-on, simulations can be expanded to additional channels such as SMS, voice, or Microsoft Teams and built into connected attack chains — which is why vishing is becoming the next front in social engineering.
In a scenario like this, email may only be the beginning. Maybe an SMS or Teams message comes next. A phone call. A QR code. And finally, the manipulated website.
Because this is increasingly how real attacks work too.
A good simulation shouldn’t prove that an employee made a mistake. It should make them behave differently when the next attack comes.
That is exactly where Behavioral Defense Engineering (BDE) comes in. Not just transferring knowledge, but practicing behavior: recognize, decide, respond, and report.
Our research together with Lucerne University of Applied Sciences and Arts (HSLU) shows that personalized, realistic interventions can improve measurable risk behavior by up to 60% — across 539 participants, the phishing rate fell from roughly 11% to 4%.
And the final step is at least as important as the first: reporting.
With CYBERDISE BDE (Behavioral Defense Engineering), suspicious messages can be reported directly from Outlook or Gmail. Employee reports can become incidents and cases, trigger automated processes, and be analyzed. Through API and SOC/SOAR integrations, these signals can flow directly into existing security processes. And how and what employees report matters just as much as whether they report at all.
The employee is no longer simply someone who is expected to avoid an attack. They become a sensor within the defense system.
And in a real incident, that can shorten the time between “Something doesn’t look right” and “Our security team knows about it.”
A CISO at a large enterprise told me that our reporting button helped shorten that time by eight hours!
The next attack will probably look different. Maybe it won’t use TerminalFix or a CAPTCHA. Maybe it will start with a QR code, followed by a phone call or an SMS.
That is why I also think it would be a mistake to turn the Berlin attack into just another “ClickFix training”.
The better answer is having the ability to quickly translate current attack methods into realistic exercises. That is exactly what we are building CYBERDISE for.
As a Swiss cybersecurity company, we are developing a product suite that enables organizations to train not only against yesterday’s attacks, but against the attack patterns their employees are actually seeing today. Our positioning sums up this ambition: “Swiss Cybersecurity Made for Europe.”
So, from my perspective, the Berlin hack doesn’t simply show that an employee made a mistake. It shows that attackers are constantly experimenting, at industrial scale, with new ways of exploiting human behavior.
Maybe we should train that behavior too. Just beforehand — and without 1.44 million published files.
So Long, Palo #humanauthored
What is a TerminalFix attack?
A TerminalFix attack is a social engineering technique that tricks a user into pasting a malicious command into the Windows Terminal themselves. A manipulated web page shows a fake CAPTCHA, copies a PowerShell command to the clipboard via JavaScript, and instructs the visitor to open a terminal and paste it. Because no file is downloaded and the user initiates the action, most email and endpoint controls never see it.
How is TerminalFix different from ClickFix?
The difference is which window the victim is sent to. Classic ClickFix uses Windows+R to open the Run dialog. TerminalFix uses Windows+X followed by I, which opens the Windows Terminal directly into PowerShell. Microsoft documented the campaign in 2026, and the BSI issued a warning on 4 September 2026. Everything else — the fake CAPTCHA, the clipboard, the pasted command — works the same way.
Was the Berlin hack really a TerminalFix attack?
Yes, according to the BSI. The agency’s published advisory of 4 September 2026 describes a compromise at “a state institution” without naming it, but the BSI confirmed on Mastodon that TerminalFix was the vector used against the Berlin Senate administrations, and linked that confirmation to the same advisory. How the attackers moved from one workstation to the full data holdings of both administrations has not been explained publicly.
Can you simulate a TerminalFix attack safely?
Yes. A simulation recreates the landing page and the fake CAPTCHA, and records what the employee does next — without any functioning malicious code. What you are measuring is the decision, not the payload: does the person follow an instruction that looks like IT, or do they stop and report it?
What should employees actually be told?
One rule covers most of it: no legitimate support process will ever ask you to paste a command into a terminal or a Run dialog because a website or a chat message told you to. Paired with an easy reporting path, that single instruction removes most of the ground a TerminalFix attack needs.
BSI, Version 1.0: Deutsche Institutionen über TerminalFix-Kampagne kompromittiert, Cybersicherheitswarnung, 4 September 2026.
heise online, BSI erklärt ersten Angriffsvektor auf Berliner Behörden, 7 September 2026 — includes the BSI’s Mastodon confirmation and the incident timeline.
Süddeutsche Zeitung, Was bisher über das Datenleck der Berliner Verwaltung bekannt ist, 5 September 2026 — 1.44 million files / approx. 5.7 TB, figures stated by the attackers.
Stacho, P. & Pugnetti, C., Leveraging AI-enabled Spearphishing to Enhance Cybersecurity, Hochschule Luzern (HSLU), CYBERDISE Awareness AG and GLB Group, Innosuisse research project 73275.1 INNO-ICT, 2025 — n = 539, four cohorts, phishing rate approx. 11% to 4%.
Further reading: How to Create a ClickFix Simulation with Cyberdise Behavioral Defense Engineering
You need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Turnstile. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Vimeo. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou need to load content from reCAPTCHA to submit the form. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Vimeo. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Bunny Stream. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Wistia. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Facebook. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Instagram. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Instagram. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Google Maps. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Google Maps. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from Google Maps. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More InformationYou are currently viewing a placeholder content from X. To access the actual content, click the button below. Please note that doing so will share data with third-party providers.
More Information