Microsoft's security team has issued a warning about a campaign called TerminalFix, and if you run a small or medium-sized business, this is worth paying close attention to. TerminalFix attacks use a technique called reverse tunnelling to quietly connect compromised machines back to attacker-controlled infrastructure — essentially punching a hidden hole through your network defences without triggering the usual alarms.
What Are TerminalFix Attacks and Why Should SMBs Care?
A reverse tunnel, in plain terms, is a connection that originates from inside your network and reaches outward to an attacker's server. Because the traffic looks like it is leaving your network rather than entering it, many firewalls and security tools simply wave it through. The TerminalFix campaign exploits this blind spot to maintain persistent, stealthy access to infected machines — often going undetected for weeks or months.
For large enterprises with dedicated security operations centres, detecting this kind of behaviour is difficult but manageable. For small and medium businesses that rely on standard firewall rules and off-the-shelf antivirus, it is a different story entirely. Attackers know this. Campaigns like TerminalFix are increasingly targeting SMBs precisely because the defences are thinner and the detection windows are wider.
How the Attack Typically Unfolds
The initial foothold usually comes from a compromised credential or a phishing email that tricks an employee into running a malicious file. Once that first step is taken, the attacker deploys a reverse tunnel tool — often a legitimate remote access utility that has been weaponised — to establish a covert communication channel back to their infrastructure.
From that point, the attacker can move laterally across your network, harvest credentials stored on the infected machine, exfiltrate sensitive data, or drop additional malware. Because the tunnel uses encrypted outbound traffic, it often blends in with normal business activity like cloud syncing or video calls. By the time anyone notices something is wrong, the damage is usually already done.
This is precisely why credential exposure is such a critical early warning signal. If a staff member's login details appear in an infostealer dump or a dark web market listing before an attacker uses them to gain that initial access, there is a window — sometimes a narrow one — to act before the intrusion begins. Monitoring for that exposure is not optional anymore; it is a frontline defence.
What SMBs Should Do Right Now
The first priority is understanding your exposure. Audit which employee accounts use reused or weak passwords. Check whether any business email addresses or credentials have appeared in known breach databases or infostealer logs. These logs, which are traded openly on dark web forums, often contain usernames, passwords, session cookies, and even autofill data harvested from infected devices.
Second, enforce multi-factor authentication across every business application — especially remote access tools, email, and any admin consoles. A reverse tunnel attack still needs that initial login to get started, and MFA significantly raises the bar.
Third, review what outbound traffic is permitted from your network. Work with your IT provider or managed service partner to flag unusual outbound connections, particularly those using non-standard ports or connecting to unfamiliar cloud infrastructure. This will not catch every case, but it reduces the window attackers have to operate undetected.
Finally, treat third-party tools with scepticism. TerminalFix and similar campaigns frequently abuse legitimate remote management software because it is trusted by default. Know what remote tools are installed on your systems and why.
Monitoring Matters More Than Ever in 2026
The TerminalFix campaign is a reminder that the threat landscape for SMBs is not static. Attackers are continuously refining techniques that exploit the gap between enterprise-grade security and the reality of what most small businesses can afford to deploy. Waiting for an incident to investigate is no longer a viable posture.
Breachrr monitors breach databases, infostealer dumps, dark web markets, public code repositories, and domain infrastructure specifically for SMBs — giving you early visibility into exposures before they become incidents. If your business credentials are out there, you need to know first.
Run a free audit at breachrr.com/audit and find out whether your business is already exposed to the kind of credential risk that TerminalFix attacks depend on.
Want to see if your company is exposed?