Historical intelligence backfill. This assessment covers reporting originally published on 2026-09-01 and was added to the RWP archive on 2026-09-07.
Late August closed with TerminalFix, fake installers, and ASCII that mail filters could not see
Week of 25 August–1 September 2026. TerminalFix kept going after the CAPTCHA. Counterfeit Razer/Edge/Kaspersky ZIPs rotated hashes. Unicode tag characters showed up in 2.3 million phish. Zimbra was still on fire.
Executive summary
FACT: The last week of August was social engineering that survived the first control. TerminalFix (28 August): fake Cloudflare CAPTCHA, LockScreenContentService, stego PNGs, AD recon, Python reverse tunnel — ClickFix that did not stop at the stealer. 1 September: look-alike .com installers for Razer/Edge/Kaspersky as regenerated ZIPs, not a one-hash IOC (Silver Fox cluster in Microsoft's framing). ASCII/Unicode tag smuggling in 2.3 million phish mails was published 3 September — just outside a Monday-dated week, included here as the mail-filter punchline landing on that weekend. Zimbra 73570 from the prior week was not done.
ASSESSMENT: Content filters that look at visible ASCII and hash-based allow-lists for “vendor installers” both failed this week.
The week in one assessment
The user still had to click. After they did, the rest was hands-on-keyboard, not a commodity stealer exit.
1. Most important development
TerminalFix as ClickFix-plus. A tunnel after recon is an intrusion, not a phish metric.
2. Active exploitation
CONFIRMED as Microsoft TI: TerminalFix and counterfeit-installer campaigns.
REPORTED Zimbra still exploited.
ASCII smuggling volume: Microsoft's 3 September number.
3. Threat actor / campaign activity
Silver Fox-style counterfeit software. ClickFix operators leveling up. No need to force a single umbrella name.
4. Vulnerabilities to prioritize
Zimbra leftover. Browser/OS for the CAPTCHA path is not a CVE — it is execution policy (constraining what Run/Terminal will accept from the clipboard).
5. Identity / cloud / enterprise
AD recon after ClickFix means the endpoint was a beachhead. Lookalike installer sites are SEO, not email.
6. Ransomware / criminal activity
Not the lead. The lead is access that ransomware affiliates will buy.
7. Defensive priorities
- Block Windows+R / Terminal paste as a user control where you can.
- Allow-list publisher certs, not ZIP hashes, for “vendor” tools.
- Mail scanning that sees Unicode tags.
- Finish Zimbra.
8. What changed from last week
From mail-server RCE and fake VPNs to post-CAPTCHA tunnels and polymorphic fake installers.
9. What we are watching next
Chrome's next 0-day and N-central's September hotfix pile (the following Monday).
10. RWP assessment
Confidence: High on the Microsoft campaign notes. This week is why identity weeklies cannot stop at “phish volume down after Tycoon2FA.”
Historical intelligence backfill of the week ending 1 September 2026; added 7 September 2026.
Sources
- Microsoft — TerminalFix reverse tunnel (28 August 2026)
- Microsoft — Counterfeit installers Silver Fox (1 September 2026)
- Microsoft — ASCII smuggling in phishing (3 September 2026 — adjacent, counted as the week's close)
- CM Alliance — Zimbra CVE-2026-73570 August exploitation