# Lorem Ipsum Multi-Stage Loader and Backdoor Delivered via SEO-Poisoned Trojanized Microsoft Teams Installers

> BlueVoyant is tracking a rapidly maturing, well-resourced mid-tier criminal threat group running a global SEO-poisoning campaign that distributes validly code-signed trojanized Microsoft Teams installers, ultimately deploying a multi-stage in-memory shellcode loader and backdoor designated 'Lorem Ipsum'. Active since at least February 2026, it opportunistically targets users searching for Microsoft Teams across at least six countries, with a US-based healthcare-sector victim confirmed and interdicted.

- **Published:** 2026-06-16T00:00:00Z
- **Last reviewed:** 2026-06-16T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0822
- **ID:** TL-2026-0822
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Vanilla Tempest
- **Detections:** 9 · **IOCs:** 27 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Lorem Ipsum is a multi-stage, in-memory shellcode loader and backdoor tracked by BlueVoyant's SOC and Threat Fusion Cell. Initial access is achieved through SEO poisoning of Bing and Google search results, where attacker-controlled fake Microsoft Teams download portals outrank legitimate results. Only the prominent download button is functional; it invokes a backend PHP script that fingerprints the downloader's IP address and serves the latest trojanized MSI once per IP, defaulting to an older build on repeat attempts.

The trojanized installers are validly signed with Microsoft ID Verified code-signing certificates issued under multiple individual identities with a maximum three-day validity (a deliberate burn-cycle that minimizes revocation exposure while appearing legitimate to Windows and EDR). Each MSI drops both a legitimate Microsoft Teams installer (run in the foreground as a distraction) and a PowerShell loader into %AppData%/Roaming, then uses a custom action to silently launch PowerShell with -WindowStyle Hidden.

The loader chain is a three-stage PowerShell decryptor. Stage one decrypts an embedded Base64 AES blob whose key and IV are NOT stored in the script but passed as command-line arguments from the MSI custom action (externalized so both the MSI and the script must be recovered to reconstruct decryption). Stage two Base64-decodes and gzip-decompresses a further payload and reflectively loads it into memory. Stage three establishes persistence by duplicating the original PowerShell command line into a Windows registry Run key, then reconstructs the final payload. Older stage-three variants stored the payload as decimal values; newer variants use a substitution-cipher decoder where a ciphertext array acts as an alphabet lookup table and a key array drives the decoding sequence ([Array]::IndexOf, modulo 256). The recovered payload contains an embedded JFIF image plus a small shellcode stub that XOR-decrypts the remainder of the shellcode using the hardcoded key 'JPEG'. Beginning late April 2026, newer iterations execute via DLL sideloading: an MSI sets a Run key value 'Microsoft Revo Health' launching 'Microsoft Teams Revo Helper ZnrAq.exe', which sideloads a malicious DLL masquerading as msvcp140.dll; the DLL stores ciphertext in its .init and .bss sections and decodes the .bss data using the .init key before transferring execution to the loader.

The Lorem Ipsum loader resolves Windows libraries via LoadLibraryA and APIs via GetProcAddress (hardcoded API strings rather than hashed names), creates a mutex via CreateMutexA whose name matches the <UUID> of its C2 /api/init/<UUID> endpoint, and abuses letsdiskuss[.]com — a legitimate India-based Q&A/blogging platform — as a dead-drop resolver. Encoded C2 data is seeded in attacker profile description fields between the delimiters -=( and )=-; the loader fetches the profile HTML, extracts the encoded strings, and applies the same substitution-cipher logic (index distance against a hardcoded reference list, converted to hex bytes) to reconstruct the real C2 domains. C2 communication is JFIF-disguised: the loader transmits its embedded image with a Content-Type: image/jpeg header, appending XOR-obfuscated data beyond the image's expected byte boundary in both directions, so commands and data are fully encapsulated in seemingly benign images. The C2 returns a JFIF with a new appended UUID; the loader writes that UUID to a %TEMP% file (session/sandbox tag), converts it via UuidFromStringA, marks the shellcode region executable with VirtualProtect, and transfers execution.

The Lorem Ipsum backdoor mirrors the loader's API-resolution routine, then generates a 32-byte AES key and IV via CryptoGenRandom (sic CryptGenRandom), appends them to its embedded image, applies the same XOR routine, and beacons to a hardcoded C2. It collects host information into JSON, Base64-encodes values via CryptBinaryToStringA, encrypts with the generated key/IV, and exfiltrates over the JFIF C2 channel in a continuing cycle. The backdoor retains VirtualProtect-based code-execution functionality for staging additional payloads; no final-stage payload was observed.

Infrastructure is disposable: NameCheap domains registered with Iceland-based Withheld-for-Privacy and weaponized within hours, one IP per domain across multiple provider ranges, with version-style rotating MSI filenames (Setup_MT_V14.63.msi, MTSetup_v15.3.7110.msi, SetupMT_V5_7765.msi) to defeat hash detection. Payload staging matured from plainraw[.]com-hosted gzip/hex PowerShell payloads (March, /raw/<hex> paths) to dedicated /api/init/{UUID} C2 endpoints (mid-April). BlueVoyant assesses with moderate confidence a relatively new but rapidly developing, adequately resourced, criminally motivated actor — possibly an initial access broker — whose ~10-week development velocity may indicate LLM-assisted tooling. Weekday-only signing timestamps clustered ~10:14-17:16 UTC weakly suggest a UTC+2 to UTC+5 operating time zone.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1583.001 Domains
- T1583.006 Web Services
- T1584 Compromise Infrastructure
- T1584.006 Web Services
- T1587.001 Malware
- T1588.002 Tool
- T1588.003 Code Signing Certificates
- T1608 Stage Capabilities
- T1608.002 Upload Tool
- T1608.006 SEO Poisoning
- T1189 Drive-by Compromise
- T1195.002 Compromise Software Supply Chain
- T1204.002 Malicious File
- T1059.001 PowerShell
- T1106 Native API
- T1547.001 Registry Run Keys / Startup Folder
- T1140 Deobfuscate/Decode Files or Information
- T1027 Obfuscated Files or Information
- T1027.004 Compile After Delivery
- T1036.005 Match Legitimate Resource Name or Location
- T1574.001 DLL
- T1553.002 Code Signing
- T1620 Reflective Code Loading
- T1218.007 Msiexec
- T1564 Hide Artifacts
- T1480 Execution Guardrails
- T1127 Trusted Developer Utilities Proxy Execution
- T1685 Disable or Modify Tools
- T1082 System Information Discovery
- T1518 Software Discovery
- T1497 Virtualization/Sandbox Evasion
- T1005 Data from Local System
- T1102.001 Dead Drop Resolver
- T1102 Web Service
- T1071.001 Web Protocols
- T1001.002 Steganography
- T1573.001 Symmetric Cryptography
- T1132.001 Standard Encoding
- T1105 Ingress Tool Transfer

## Sources

- [Lorem Ipsum Malware: Trojanized MS Teams Installers Deliver Multi-Stage Loader and Backdoor](https://www.bluevoyant.com/blog/lorem-ipsum-trojanized-microsoft-teams-installers-multi-stage-loader-backdoor)
- [MITRE ATT&CK T1102.001 Web Service: Dead Drop Resolver](https://attack.mitre.org/techniques/T1102/001/)
- [MITRE ATT&CK T1574.002 Hijack Execution Flow: DLL Side-Loading](https://attack.mitre.org/techniques/T1574/002/)
- [MITRE ATT&CK T1608.006 Stage Capabilities: SEO Poisoning](https://attack.mitre.org/techniques/T1608/006/)
- [MITRE ATT&CK T1553.002 Subvert Trust Controls: Code Signing](https://attack.mitre.org/techniques/T1553/002/)
- [VirusTotal search: Tms_Setup__V5.4.140.msi (Lorem Ipsum trojanized installer)](https://www.virustotal.com/gui/search?query=name%3A%22Tms_Setup__V5.4.140.msi%22)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0822
