Historical intelligence backfill. This assessment covers reporting originally published on 2026-09-01 and was added to the RWP archive on 2026-09-07.

IT Intelligence · IT

Late August closed with TerminalFix, fake installers, and ASCII that mail filters could not see

Week of 25 August–1 September 2026. TerminalFix kept going after the CAPTCHA. Counterfeit Razer/Edge/Kaspersky ZIPs rotated hashes. Unicode tag characters showed up in 2.3 million phish. Zimbra was still on fire.

RWP Ventures · 2026-09-07 · event 2026-09-01 · 2 min read · priority 8.0

Executive summary

FACT: The last week of August was social engineering that survived the first control. TerminalFix (28 August): fake Cloudflare CAPTCHA, LockScreenContentService, stego PNGs, AD recon, Python reverse tunnel — ClickFix that did not stop at the stealer. 1 September: look-alike .com installers for Razer/Edge/Kaspersky as regenerated ZIPs, not a one-hash IOC (Silver Fox cluster in Microsoft's framing). ASCII/Unicode tag smuggling in 2.3 million phish mails was published 3 September — just outside a Monday-dated week, included here as the mail-filter punchline landing on that weekend. Zimbra 73570 from the prior week was not done.

ASSESSMENT: Content filters that look at visible ASCII and hash-based allow-lists for “vendor installers” both failed this week.

The week in one assessment

The user still had to click. After they did, the rest was hands-on-keyboard, not a commodity stealer exit.

1. Most important development

TerminalFix as ClickFix-plus. A tunnel after recon is an intrusion, not a phish metric.

2. Active exploitation

CONFIRMED as Microsoft TI: TerminalFix and counterfeit-installer campaigns.

REPORTED Zimbra still exploited.

ASCII smuggling volume: Microsoft's 3 September number.

3. Threat actor / campaign activity

Silver Fox-style counterfeit software. ClickFix operators leveling up. No need to force a single umbrella name.

4. Vulnerabilities to prioritize

Zimbra leftover. Browser/OS for the CAPTCHA path is not a CVE — it is execution policy (constraining what Run/Terminal will accept from the clipboard).

5. Identity / cloud / enterprise

AD recon after ClickFix means the endpoint was a beachhead. Lookalike installer sites are SEO, not email.

6. Ransomware / criminal activity

Not the lead. The lead is access that ransomware affiliates will buy.

7. Defensive priorities

  1. Block Windows+R / Terminal paste as a user control where you can.
  2. Allow-list publisher certs, not ZIP hashes, for “vendor” tools.
  3. Mail scanning that sees Unicode tags.
  4. Finish Zimbra.

8. What changed from last week

From mail-server RCE and fake VPNs to post-CAPTCHA tunnels and polymorphic fake installers.

9. What we are watching next

Chrome's next 0-day and N-central's September hotfix pile (the following Monday).

10. RWP assessment

Confidence: High on the Microsoft campaign notes. This week is why identity weeklies cannot stop at “phish volume down after Tycoon2FA.”

Historical intelligence backfill of the week ending 1 September 2026; added 7 September 2026.

Sources

  1. Microsoft — TerminalFix reverse tunnel (28 August 2026)
  2. Microsoft — Counterfeit installers Silver Fox (1 September 2026)
  3. Microsoft — ASCII smuggling in phishing (3 September 2026 — adjacent, counted as the week's close)
  4. CM Alliance — Zimbra CVE-2026-73570 August exploitation