Threat reportMalwareTL-2026-0822

Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via SEO-Poisoned Trojanized Microsoft Teams Installers

highACTIVE

Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via (TL-2026-0822), also tracked as Lorem Ipsum loader, is a high-severity malware campaign, first published 2026-06-16. It is attributed to Vanilla Tempest with high confidence, affects Microsoft Windows (endpoints running trojanized Microsoft Teams, maps to 41 MITRE ATT&CK techniques (T1001.002, T1005, T1027), and is covered by 9 detection rules and 27 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
41MITRE ATT&CK
Actors
1Vanilla Tempest
Detection rules
9SPL · KQL · Sigma
IOCs
27Indicators of compromise

Key facts for TL-2026-0822

Threat ID
TL-2026-0822
Also known as
Lorem Ipsum loader, Lorem Ipsum backdoor
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
Vanilla Tempest
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
healthcare, any (opportunistic global SEO targeting)
Target regions
North America, Europe, Asia
Detection rules
9
Indicators of compromise
27

Malware and tooling in Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via

Malware and tooling: Lorem Ipsum

How Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via works

BlueVoyant is tracking a rapidly maturing, well-resourced mid-tier criminal threat group running a global SEO-poisoning campaign that distributes validly code-signed trojanized Microsoft Teams installers, ultimately deploying a multi-stage in-memory shellcode loader and backdoor designated 'Lorem Ipsum'. Active since at least February 2026, it opportunistically targets users searching for Microsoft Teams across at least six countries, with a US-based healthcare-sector victim confirmed and interdicted.

Lorem Ipsum is a multi-stage, in-memory shellcode loader and backdoor tracked by BlueVoyant's SOC and Threat Fusion Cell. Initial access is achieved through SEO poisoning of Bing and Google search results, where attacker-controlled fake Microsoft Teams download portals outrank legitimate results. Only the prominent download button is functional; it invokes a backend PHP script that fingerprints the downloader's IP address and serves the latest trojanized MSI once per IP, defaulting to an older build on repeat attempts.

The trojanized installers are validly signed with Microsoft ID Verified code-signing certificates issued under multiple individual identities with a maximum three-day validity (a deliberate burn-cycle that minimizes revocation exposure while appearing legitimate to Windows and EDR). Each MSI drops both a legitimate Microsoft Teams installer (run in the foreground as a distraction) and a PowerShell loader into %AppData%/Roaming, then uses a custom action to silently launch PowerShell with -WindowStyle Hidden.

The loader chain is a three-stage PowerShell decryptor. Stage one decrypts an embedded Base64 AES blob whose key and IV are NOT stored in the script but passed as command-line arguments from the MSI custom action (externalized so both the MSI and the script must be recovered to reconstruct decryption). Stage two Base64-decodes and gzip-decompresses a further payload and reflectively loads it into memory. Stage three establishes persistence by duplicating the original PowerShell command line into a Windows registry Run key, then reconstructs the final payload. Older stage-three variants stored the payload as decimal values; newer variants use a substitution-cipher decoder where a ciphertext array acts as an alphabet lookup table and a key array drives the decoding sequence ([Array]::IndexOf, modulo 256). The recovered payload contains an embedded JFIF image plus a small shellcode stub that XOR-decrypts the remainder of the shellcode using the hardcoded key 'JPEG'. Beginning late April 2026, newer iterations execute via DLL sideloading: an MSI sets a Run key value 'Microsoft Revo Health' launching 'Microsoft Teams Revo Helper ZnrAq.exe', which sideloads a malicious DLL masquerading as msvcp140.dll; the DLL stores ciphertext in its .init and .bss sections and decodes the .bss data using the .init key before transferring execution to the loader.

The Lorem Ipsum loader resolves Windows libraries via LoadLibraryA and APIs via GetProcAddress (hardcoded API strings rather than hashed names), creates a mutex via CreateMutexA whose name matches the <UUID> of its C2 /api/init/<UUID> endpoint, and abuses letsdiskuss[.]com — a legitimate India-based Q&A/blogging platform — as a dead-drop resolver. Encoded C2 data is seeded in attacker profile description fields between the delimiters -=( and )=-; the loader fetches the profile HTML, extracts the encoded strings, and applies the same substitution-cipher logic (index distance against a hardcoded reference list, converted to hex bytes) to reconstruct the real C2 domains. C2 communication is JFIF-disguised: the loader transmits its embedded image with a Content-Type: image/jpeg header, appending XOR-obfuscated data beyond the image's expected byte boundary in both directions, so commands and data are fully encapsulated in seemingly benign images. The C2 returns a JFIF with a new appended UUID; the loader writes that UUID to a %TEMP% file (session/sandbox tag), converts it via UuidFromStringA, marks the shellcode region executable with VirtualProtect, and transfers execution.

The Lorem Ipsum backdoor mirrors the loader's API-resolution routine, then generates a 32-byte AES key and IV via CryptoGenRandom (sic CryptGenRandom), appends them to its embedded image, applies the same XOR routine, and beacons to a hardcoded C2. It collects host information into JSON, Base64-encodes values via CryptBinaryToStringA, encrypts with the generated key/IV, and exfiltrates over the JFIF C2 channel in a continuing cycle. The backdoor retains VirtualProtect-based code-execution functionality for staging additional payloads; no final-stage payload was observed.

Infrastructure is disposable: NameCheap domains registered with Iceland-based Withheld-for-Privacy and weaponized within hours, one IP per domain across multiple provider ranges, with version-style rotating MSI filenames (Setup_MT_V14.63.msi, MTSetup_v15.3.7110.msi, SetupMT_V5_7765.msi) to defeat hash detection. Payload staging matured from plainraw[.]com-hosted gzip/hex PowerShell payloads (March, /raw/<hex> paths) to dedicated /api/init/{UUID} C2 endpoints (mid-April). BlueVoyant assesses with moderate confidence a relatively new but rapidly developing, adequately resourced, criminally motivated actor — possibly an initial access broker — whose ~10-week development velocity may indicate LLM-assisted tooling. Weekday-only signing timestamps clustered ~10:14-17:16 UTC weakly suggest a UTC+2 to UTC+5 operating time zone.

MITRE ATT&CK techniques used in TL-2026-0822

Command and Control

T1001.002 Steganography; T1071.001 Web Protocols; T1102 Web Service; T1102.001 Dead Drop Resolver; T1105 Ingress Tool Transfer; T1132.001 Standard Encoding; T1573.001 Symmetric Cryptography

Collection

T1005 Data from Local System

Defense Evasion

T1027 Obfuscated Files or Information; T1027.004 Compile After Delivery; T1036.005 Match Legitimate Resource Name or Location; T1127 Trusted Developer Utilities Proxy Execution; T1140 Deobfuscate/Decode Files or Information; T1218.007 Msiexec; T1480 Execution Guardrails; T1564 Hide Artifacts; T1620 Reflective Code Loading

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059.001 PowerShell; T1106 Native API; T1204.002 Malicious File

Discovery

T1082 System Information Discovery; T1497 Virtualization/Sandbox Evasion; T1518 Software Discovery

Initial Access

T1189 Drive-by Compromise; T1195.002 Compromise Software Supply Chain

Persistence

T1547.001 Registry Run Keys / Startup Folder

defense-impairment

T1553.002 Code Signing; T1685 Disable or Modify Tools

stealth

T1574.001 DLL

Resource Development

T1583 Acquire Infrastructure; T1583.001 Domains; T1583.006 Web Services; T1584 Compromise Infrastructure; T1584.006 Web Services; T1587.001 Malware; T1588.002 Tool; T1588.003 Code Signing Certificates; T1608 Stage Capabilities; T1608.002 Upload Tool; T1608.006 SEO Poisoning

Affected products and versions in Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via

  • Microsoft — Windows (endpoints running trojanized Microsoft Teams installers)
    Vulnerable versions: Windows (all supported; social-engineering / signed-installer abuse, not a product vulnerability)

Remediation for Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via

Immediate actions

  • Block the documented C2 and staging domains (official-teams-storage[.]com, graburban[.]com, valeurban[.]com, semigoddess[.]com, reeeeealy[.]com, biblegodlike[.]com, plainraw[.]com) at DNS/proxy/perimeter
  • Alert on and block non-browser process traffic to letsdiskuss[.]com/user/* (legitimate platform abused as a dead-drop resolver; do not blanket-block the domain for users)
  • Hunt for the Run key value 'Microsoft Revo Health' and the binary 'Microsoft Teams Revo Helper ZnrAq.exe' and a non-system msvcp140.dll loaded from %AppData%/Roaming
  • Quarantine the documented MSI SHA256 hashes and any PowerShell loaders dropped to %AppData%/Roaming

Workarounds

  • Application allowlisting to prevent execution of unsigned/short-lived-signed installers and unexpected DLL sideloading from user-writable directories
  • Restrict or monitor msiexec custom-action PowerShell execution via attack-surface-reduction rules

Longer-term hardening

  • Deploy behavioral EDR detections for -WindowStyle Hidden PowerShell spawned from msiexec.exe writing into %AppData%/Roaming
  • Detect JFIF/image-content POSTs (Content-Type: image/jpeg) to non-image API endpoints and the /api/init/{UUID} callback pattern
  • Treat short-validity (<=3 day) Microsoft ID Verified code-signing certificates as a high-risk signal rather than a trust anchor
  • Block software downloads from non-vendor domains via SEO-poisoned search results; steer users to official Microsoft Teams distribution only

Weaknesses (CWE) in Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via

CWE-506, CWE-427

Timeline of Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via

  • BlueVoyant identifies earliest test build: a malicious binary masquerading as the legitimate utility 'PE Detective', minimally obfuscated by modifying the Address of Entry Point to redirect into appended code. Assessed with high confidence as one of the threat group's earliest test builds.
  • Attacker-controlled letsdiskuss[.]com dead-drop profiles (joeblack1673, stevenblake8483, dhuahsd12d2752, stevenseagal4596) begin appearing with staggered first-seen activity from mid-March through late April 2026.
  • Trojanized Microsoft Teams MSI installers with a functional multi-stage PowerShell loader observed in the wild; early versions carry fewer anti-analysis methods and stage gzip/hex-encoded PowerShell payloads from plainraw[.]com under /raw/<hex> paths.
  • Updated installers add anti-analysis techniques, including stripping PowerShell command-line arguments that supply the AES key/IV, and introduce substitution-cipher decoding plus XOR-encrypted shellcode stubs (hardcoded XOR key 'JPEG').
  • By the April 15-16 iteration, plainraw[.]com is dropped from telemetry; operators shift to dedicated per-victim /api/init/{UUID} C2 callback endpoints, improving victim tracking and infrastructure segmentation.
  • Late-April iterations execute the loader via DLL sideloading: a Run key value 'Microsoft Revo Health' launches 'Microsoft Teams Revo Helper ZnrAq.exe', which sideloads a malicious DLL masquerading as msvcp140.dll (ciphertext in .init/.bss sections).
  • Public scanning telemetry shows campaign indicators across at least six countries spanning North America, Europe, and Asia between March and late April 2026; a US-based healthcare-sector BlueVoyant client is confirmed targeted and the attack interdicted.
  • BlueVoyant publishes its analysis of the Lorem Ipsum trojanized Microsoft Teams loader and backdoor campaign.

Sources cited for Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via

Detection coverage for TL-2026-0822

As of 2026-06-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0822 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
27 indicators of compromise · Red and above. Compare plans

Community OSINT corroboration for TL-2026-0822

2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats