ClickFix Cluster Uses DLL Sideloading and Compromised WordPress Sites to Deliver Lorem Ipsum Loader, Linked to Vanilla Tempest

ClickFix Cluster Uses DLL Sideloading and Compromised (TL-2026-2199), also tracked as Lorem Ipsum Loader ClickFix cluster, is a high-severity malware campaign, first published 2026-08-29. It is attributed to Vanilla Tempest with medium confidence, affects WordPress Self-hosted WordPress sites (compromised for drive-by, maps to 15 MITRE ATT&CK techniques (T1053.005, T1059.003, T1059.006), and is covered by 9 detection rules and 33 indicators of compromise.

Key facts for TL-2026-2199

Threat ID
TL-2026-2199
Also known as
Lorem Ipsum Loader ClickFix cluster
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-08-29
Last reviewed
2026-08-29
Attribution
Vanilla Tempest
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
architecture, legal services, construction technology, health, education, it
Detection rules
9
Indicators of compromise
33

Malware and tooling in ClickFix Cluster Uses DLL Sideloading and Compromised

Malware and tooling: INC Ransomware - S1139, GootLoader

Field Effect tracked three distinct ClickFix social-engineering campaigns (June-July 2026) that share file-naming conventions, DLL sideloading via renamed legitimate binaries, and command-and-control dead drops hosted on digitalpoint.com forum profiles. The cluster overlaps with BlueVoyant's Lorem Ipsum loader and, via the Supper backdoor, is attributed to the financially motivated ransomware actor Vanilla Tempest (aka Rapid Brigantine, DEV-0832, Vice Society).

How ClickFix Cluster Uses DLL Sideloading and Compromised works

Field Effect's 2026-08-24 report documents a ClickFix cluster comprising three distinct campaigns observed between mid-June and July 2026, unified by shared naming conventions, a common DLL-sideloading pattern, and a shared command-and-control (C2) dead-drop resolver hosted on the digitalpoint.com forum. Campaign 1 (mid-June 2026) delivered remotely hosted MSI packages via a ClickFix clipboard prompt invoking `MsieXEc.ExE /pAckAGe`, abusing legitimate installers for 3D PDF Maker Smart, Bitwarden VPN, and ESET SysInspector to sideload a malicious mscoree.dll alongside a renamed copy of Microsoft's ClickOnce Launch Utility (masquerading as 'NET Runtime Optimization Service.exe'). Persistence was established via a scheduled task, a hidden ProgramData subfolder was created with attrib.exe (+h +s), and PowerShell executed dsregcmd.exe /status for host discovery; Field Effect documented an approximately six-day dwell time before loader deployment. Campaign 2 (late June 2026) shared Campaign 1's infrastructure and mscoree.dll/ClickOnce sideload chain but delivered payloads via PowerShell downloading and executing an outdated NodeJS v7.10.1 runtime alongside a malicious update.js. Campaign 3 (July 2026) used a compromised WordPress site serving JavaScript from /js/all.min.js that performed Polygon-blockchain-based C2 domain retrieval, fingerprinted the victim (RAM, CPU, browser language/user agent), and served a localized ClickFix lure leading to an embedded Python 3.5 install, an obfuscated Captcha.py payload, and DLL sideloading via LockScreenContentServer.exe; persistence used a Run registry key plus an hourly scheduled task, with second-stage infrastructure hosted at cooldogshistory.com. Across all three campaigns, post-compromise activity included Active Directory and host-discovery commands (nltest.exe /dclist:, net.exe group "domain admins" /domain, nltest /domain_trusts, ipconfig.exe, net.exe user <user> /domain, net.exe localgroup administrators) and an ADSI-searcher PowerShell query for user accounts with populated description fields. C2 used a dead-drop resolver technique on digitalpoint.com forum member profiles (digitalpoint.com/members/trytodetectme.1134520, digitalpoint.com/members/documentpublisher.1139897), where encoded, space-delimited strings in the profile info tab decode to live C2 domains; victims subsequently POST JFIF-disguised uploads to /api/init/<guid>. Prior reporting on this same dead-drop technique (tracked by BlueVoyant against the Lorem Ipsum loader) documents the resolver platform migrating from letsdiskuss.com to digitalpoint.com after public disclosure, while retaining the '-=(' / ')=-' delimiter convention, substitution-cipher decoding, one-profile-to-one-C2-cluster mapping, and per-victim beaconing to three redundant Cloudflare-fronted C2 domains. Field Effect ties this cluster to BlueVoyant's Lorem Ipsum loader family, active since February 2026 and originally delivered via trojanized, fraudulently code-signed Microsoft Teams installers before pivoting to ClickFix after Microsoft disrupted the malware-signing service the operators relied on. BlueVoyant and other reporting attribute Lorem Ipsum/ClickFix activity to Rapid Brigantine, also tracked as Vanilla Tempest, DEV-0832, Vice Society, and Vice Spider, and describe Lorem Ipsum's DLL side-loading chains (observed using both mscoree.dll and msvcp140.dll variants) as leading to ransomware deployment (Rhysida, BlackCat, Zeppelin, Quantum Locker in BlueVoyant's broader Lorem Ipsum tracking). Independently, Microsoft has attributed the Active Directory/domain-trust enumeration TTPs and the Supper backdoor specifically to Vanilla Tempest, a financially motivated actor that receives handoffs from Storm-0494 (Gootloader) intrusions and has deployed INC ransomware against U.S. healthcare targets, using AnyDesk, MEGA, RDP, and WMI for lateral movement and exfiltration ahead of ransomware detonation. Field Effect's cluster does not itself confirm ransomware deployment; the Vanilla Tempest link is via TTP/tooling overlap (Supper backdoor behavior and AD enumeration patterns), not a directly observed ransomware payload in these three campaigns.

MITRE ATT&CK techniques used in TL-2026-2199

Persistence

T1053.005 Scheduled Task/Job: Scheduled Task; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Execution

T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1059.006 Command and Scripting Interpreter: Python; T1059.007 Command and Scripting Interpreter: JavaScript; T1204.004 User Execution: Malicious Copy and Paste

Discovery

T1069.002 Permission Groups Discovery: Domain Groups; T1087.002 Account Discovery: Domain Account; T1482 Domain Trust Discovery

Command and Control

T1102.001 Web Service: Dead Drop Resolver

Defense Evasion

T1218.007 System Binary Proxy Execution: Msiexec; T1564.004 Hide Artifacts: NTFS File Attributes

stealth

T1574.001 Hijack Execution Flow: DLL

Resource Development

T1583.006 Acquire Infrastructure: Web Services

Reconnaissance

T1681 Search Threat Vendor Data

Affected products and versions in ClickFix Cluster Uses DLL Sideloading and Compromised

  • WordPress — Self-hosted WordPress sites (compromised for drive-by delivery)
    Vulnerable versions: Not a WordPress-core CVE — arbitrary compromised sites used as a delivery host
  • Microsoft — Windows (target OS for MSI/DLL-sideload payload chain)
    Vulnerable versions: All Windows versions reachable via ClickFix social engineering

Remediation for ClickFix Cluster Uses DLL Sideloading and Compromised

Patches

  • No vendor CVE/patch applies — this is a social-engineering and living-off-the-land delivery campaign, not a software vulnerability

Immediate actions

  • Block the IOC domains and IPs in threat_iocs at DNS/proxy/perimeter firewall
  • Alert on/block outbound traffic to digitalpoint.com/members/trytodetectme.1134520 and digitalpoint.com/members/documentpublisher.1139897, and to /api/init/<guid> upload paths
  • Hunt via EDR for the listed SHA256 hashes and for the sideloading host processes (3DPDFMakerSmart.exe, 'NET Runtime Optimization Service.exe', LockScreenContentServer.exe) loading mscoree.dll/dui70.dll from non-standard paths
  • Deploy detections for ClickFix-style user execution (clipboard-paste into Run dialog or terminal) and for msiexec.exe invoked with remote /package URLs

Workarounds

  • User-awareness training specifically covering ClickFix/fake-CAPTCHA copy-paste prompts and unsolicited phone contact directing users to attacker-controlled 'photo/document' sites
  • Restrict or log Windows Run-dialog and clipboard-to-terminal execution on high-risk endpoints where feasible

Longer-term hardening

  • Deploy application allowlisting/EDR DLL side-load protection to block unsigned or renamed ClickOnce Launch Utility and other LOLBins executing from ProgramData
  • Monitor for scheduled-task and Run-key persistence created by non-standard installers, and for hidden (+h +s) ProgramData subfolders
  • Harden and continuously integrity-monitor WordPress installations (plugins, themes, WAF) given confirmed use of a compromised WordPress site as a delivery vector
  • Threat-hunt for downstream Vanilla Tempest / Supper-backdoor indicators (AnyDesk, MEGA, RDP + WMI lateral movement) given the attributed ransomware follow-on risk

Timeline of ClickFix Cluster Uses DLL Sideloading and Compromised

  • BlueVoyant tracks the Lorem Ipsum loader campaign beginning, initially delivered via trojanized Microsoft Teams installers using fraudulently obtained code-signing certificates.
  • Microsoft disrupts the malware-signing-as-a-service operation the Lorem Ipsum operators relied on for signed installers, forcing a pivot from trojanized installers to ClickFix-based delivery.
  • Field Effect observes Campaign 1: ClickFix clipboard prompts invoking msiexec.exe to fetch remote MSI packages abusing 3D PDF Maker Smart, Bitwarden VPN, and ESET SysInspector to sideload mscoree.dll via a renamed ClickOnce Launch Utility.
  • Field Effect documents an approximately six-day dwell time in Campaign 1 intrusions between initial MSI-based compromise and loader deployment, with a hidden ProgramData subfolder created via attrib.exe (+h +s).
  • Field Effect observes Campaign 2, sharing Campaign 1's infrastructure: PowerShell downloads an outdated NodeJS v7.10.1 runtime and executes a malicious update.js alongside the same mscoree.dll sideload chain.
  • Field Effect observes Campaign 3: a compromised WordPress site serves JavaScript (/js/all.min.js) using Polygon blockchain-based C2 domain retrieval, victim fingerprinting, and a localized ClickFix lure leading to an embedded Python 3.5 install, obfuscated Captcha.py, and LockScreenContentServer.exe DLL sideloading with Run-key and hourly-scheduled-task persistence.
  • Field Effect publishes 'A ClickFix cluster,' correlating all three campaigns via shared naming conventions, DLL sideloading, and digitalpoint.com dead-drop C2, and links the cluster to BlueVoyant's Lorem Ipsum loader and, via the Supper backdoor, to Vanilla Tempest.

Sources cited for ClickFix Cluster Uses DLL Sideloading and Compromised

More in malware

Detection coverage for TL-2026-2199

As of 2026-08-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2199 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats