ClickFix Cluster Uses DLL Sideloading and Compromised WordPress Sites to Deliver Lorem Ipsum Loader, Linked to Vanilla Tempest
ClickFix Cluster Uses DLL Sideloading and Compromised (TL-2026-2199), also tracked as Lorem Ipsum Loader ClickFix cluster, is a high-severity malware campaign, first published 2026-08-29. It is attributed to Vanilla Tempest with medium confidence, affects WordPress Self-hosted WordPress sites (compromised for drive-by, maps to 15 MITRE ATT&CK techniques (T1053.005, T1059.003, T1059.006), and is covered by 9 detection rules and 33 indicators of compromise.
Key facts for TL-2026-2199
- Threat ID
- TL-2026-2199
- Also known as
- Lorem Ipsum Loader ClickFix cluster
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-08-29
- Last reviewed
- 2026-08-29
- Attribution
- Vanilla Tempest
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- architecture, legal services, construction technology, health, education, it
- Detection rules
- 9
- Indicators of compromise
- 33
Malware and tooling in ClickFix Cluster Uses DLL Sideloading and Compromised
Malware and tooling: INC Ransomware - S1139, GootLoader
Field Effect tracked three distinct ClickFix social-engineering campaigns (June-July 2026) that share file-naming conventions, DLL sideloading via renamed legitimate binaries, and command-and-control dead drops hosted on digitalpoint.com forum profiles. The cluster overlaps with BlueVoyant's Lorem Ipsum loader and, via the Supper backdoor, is attributed to the financially motivated ransomware actor Vanilla Tempest (aka Rapid Brigantine, DEV-0832, Vice Society).
How ClickFix Cluster Uses DLL Sideloading and Compromised works
Field Effect's 2026-08-24 report documents a ClickFix cluster comprising three distinct campaigns observed between mid-June and July 2026, unified by shared naming conventions, a common DLL-sideloading pattern, and a shared command-and-control (C2) dead-drop resolver hosted on the digitalpoint.com forum. Campaign 1 (mid-June 2026) delivered remotely hosted MSI packages via a ClickFix clipboard prompt invoking `MsieXEc.ExE /pAckAGe`, abusing legitimate installers for 3D PDF Maker Smart, Bitwarden VPN, and ESET SysInspector to sideload a malicious mscoree.dll alongside a renamed copy of Microsoft's ClickOnce Launch Utility (masquerading as 'NET Runtime Optimization Service.exe'). Persistence was established via a scheduled task, a hidden ProgramData subfolder was created with attrib.exe (+h +s), and PowerShell executed dsregcmd.exe /status for host discovery; Field Effect documented an approximately six-day dwell time before loader deployment. Campaign 2 (late June 2026) shared Campaign 1's infrastructure and mscoree.dll/ClickOnce sideload chain but delivered payloads via PowerShell downloading and executing an outdated NodeJS v7.10.1 runtime alongside a malicious update.js. Campaign 3 (July 2026) used a compromised WordPress site serving JavaScript from /js/all.min.js that performed Polygon-blockchain-based C2 domain retrieval, fingerprinted the victim (RAM, CPU, browser language/user agent), and served a localized ClickFix lure leading to an embedded Python 3.5 install, an obfuscated Captcha.py payload, and DLL sideloading via LockScreenContentServer.exe; persistence used a Run registry key plus an hourly scheduled task, with second-stage infrastructure hosted at cooldogshistory.com. Across all three campaigns, post-compromise activity included Active Directory and host-discovery commands (nltest.exe /dclist:, net.exe group "domain admins" /domain, nltest /domain_trusts, ipconfig.exe, net.exe user <user> /domain, net.exe localgroup administrators) and an ADSI-searcher PowerShell query for user accounts with populated description fields. C2 used a dead-drop resolver technique on digitalpoint.com forum member profiles (digitalpoint.com/members/trytodetectme.1134520, digitalpoint.com/members/documentpublisher.1139897), where encoded, space-delimited strings in the profile info tab decode to live C2 domains; victims subsequently POST JFIF-disguised uploads to /api/init/<guid>. Prior reporting on this same dead-drop technique (tracked by BlueVoyant against the Lorem Ipsum loader) documents the resolver platform migrating from letsdiskuss.com to digitalpoint.com after public disclosure, while retaining the '-=(' / ')=-' delimiter convention, substitution-cipher decoding, one-profile-to-one-C2-cluster mapping, and per-victim beaconing to three redundant Cloudflare-fronted C2 domains. Field Effect ties this cluster to BlueVoyant's Lorem Ipsum loader family, active since February 2026 and originally delivered via trojanized, fraudulently code-signed Microsoft Teams installers before pivoting to ClickFix after Microsoft disrupted the malware-signing service the operators relied on. BlueVoyant and other reporting attribute Lorem Ipsum/ClickFix activity to Rapid Brigantine, also tracked as Vanilla Tempest, DEV-0832, Vice Society, and Vice Spider, and describe Lorem Ipsum's DLL side-loading chains (observed using both mscoree.dll and msvcp140.dll variants) as leading to ransomware deployment (Rhysida, BlackCat, Zeppelin, Quantum Locker in BlueVoyant's broader Lorem Ipsum tracking). Independently, Microsoft has attributed the Active Directory/domain-trust enumeration TTPs and the Supper backdoor specifically to Vanilla Tempest, a financially motivated actor that receives handoffs from Storm-0494 (Gootloader) intrusions and has deployed INC ransomware against U.S. healthcare targets, using AnyDesk, MEGA, RDP, and WMI for lateral movement and exfiltration ahead of ransomware detonation. Field Effect's cluster does not itself confirm ransomware deployment; the Vanilla Tempest link is via TTP/tooling overlap (Supper backdoor behavior and AD enumeration patterns), not a directly observed ransomware payload in these three campaigns.
MITRE ATT&CK techniques used in TL-2026-2199
Persistence
T1053.005 Scheduled Task/Job: Scheduled Task; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Execution
T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1059.006 Command and Scripting Interpreter: Python; T1059.007 Command and Scripting Interpreter: JavaScript; T1204.004 User Execution: Malicious Copy and Paste
Discovery
T1069.002 Permission Groups Discovery: Domain Groups; T1087.002 Account Discovery: Domain Account; T1482 Domain Trust Discovery
Command and Control
T1102.001 Web Service: Dead Drop Resolver
Defense Evasion
T1218.007 System Binary Proxy Execution: Msiexec; T1564.004 Hide Artifacts: NTFS File Attributes
stealth
T1574.001 Hijack Execution Flow: DLL
Resource Development
T1583.006 Acquire Infrastructure: Web Services
Reconnaissance
Affected products and versions in ClickFix Cluster Uses DLL Sideloading and Compromised
- WordPress — Self-hosted WordPress sites (compromised for drive-by delivery)
Vulnerable versions: Not a WordPress-core CVE — arbitrary compromised sites used as a delivery host - Microsoft — Windows (target OS for MSI/DLL-sideload payload chain)
Vulnerable versions: All Windows versions reachable via ClickFix social engineering
Remediation for ClickFix Cluster Uses DLL Sideloading and Compromised
Patches
- No vendor CVE/patch applies — this is a social-engineering and living-off-the-land delivery campaign, not a software vulnerability
Immediate actions
- Block the IOC domains and IPs in threat_iocs at DNS/proxy/perimeter firewall
- Alert on/block outbound traffic to digitalpoint.com/members/trytodetectme.1134520 and digitalpoint.com/members/documentpublisher.1139897, and to /api/init/<guid> upload paths
- Hunt via EDR for the listed SHA256 hashes and for the sideloading host processes (3DPDFMakerSmart.exe, 'NET Runtime Optimization Service.exe', LockScreenContentServer.exe) loading mscoree.dll/dui70.dll from non-standard paths
- Deploy detections for ClickFix-style user execution (clipboard-paste into Run dialog or terminal) and for msiexec.exe invoked with remote /package URLs
Workarounds
- User-awareness training specifically covering ClickFix/fake-CAPTCHA copy-paste prompts and unsolicited phone contact directing users to attacker-controlled 'photo/document' sites
- Restrict or log Windows Run-dialog and clipboard-to-terminal execution on high-risk endpoints where feasible
Longer-term hardening
- Deploy application allowlisting/EDR DLL side-load protection to block unsigned or renamed ClickOnce Launch Utility and other LOLBins executing from ProgramData
- Monitor for scheduled-task and Run-key persistence created by non-standard installers, and for hidden (+h +s) ProgramData subfolders
- Harden and continuously integrity-monitor WordPress installations (plugins, themes, WAF) given confirmed use of a compromised WordPress site as a delivery vector
- Threat-hunt for downstream Vanilla Tempest / Supper-backdoor indicators (AnyDesk, MEGA, RDP + WMI lateral movement) given the attributed ransomware follow-on risk
Timeline of ClickFix Cluster Uses DLL Sideloading and Compromised
- BlueVoyant tracks the Lorem Ipsum loader campaign beginning, initially delivered via trojanized Microsoft Teams installers using fraudulently obtained code-signing certificates.
- Microsoft disrupts the malware-signing-as-a-service operation the Lorem Ipsum operators relied on for signed installers, forcing a pivot from trojanized installers to ClickFix-based delivery.
- Field Effect observes Campaign 1: ClickFix clipboard prompts invoking msiexec.exe to fetch remote MSI packages abusing 3D PDF Maker Smart, Bitwarden VPN, and ESET SysInspector to sideload mscoree.dll via a renamed ClickOnce Launch Utility.
- Field Effect documents an approximately six-day dwell time in Campaign 1 intrusions between initial MSI-based compromise and loader deployment, with a hidden ProgramData subfolder created via attrib.exe (+h +s).
- Field Effect observes Campaign 2, sharing Campaign 1's infrastructure: PowerShell downloads an outdated NodeJS v7.10.1 runtime and executes a malicious update.js alongside the same mscoree.dll sideload chain.
- Field Effect observes Campaign 3: a compromised WordPress site serves JavaScript (/js/all.min.js) using Polygon blockchain-based C2 domain retrieval, victim fingerprinting, and a localized ClickFix lure leading to an embedded Python 3.5 install, obfuscated Captcha.py, and LockScreenContentServer.exe DLL sideloading with Run-key and hourly-scheduled-task persistence.
- Field Effect publishes 'A ClickFix cluster,' correlating all three campaigns via shared naming conventions, DLL sideloading, and digitalpoint.com dead-drop C2, and links the cluster to BlueVoyant's Lorem Ipsum loader and, via the Supper backdoor, to Vanilla Tempest.
Sources cited for ClickFix Cluster Uses DLL Sideloading and Compromised
- A ClickFix cluster: Observed activity from recent ClickFix campaigns
- Malpedia library entry: A ClickFix cluster (win.lorem_ipsum)
- Lorem Ipsum Revisited: ClickFix Pivot & Rapid Brigantine
- Lorem Ipsum Malware: Trojanized MS Teams Installers, Multi-Stage Loader & Backdoor
- 'Lorem Ipsum' Malware Pivots to ClickFix Delivery
- ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures
- Rapid Brigantine ties ClickFix malware to fake updates
- ClickFix Campaigns Deliver BabaDeda, Lorem Ipsum, and Potemkin Loaders
- Microsoft: Vanilla Tempest hackers hit healthcare with INC ransomware
- Microsoft: US Healthcare Sector Targeted by INC Ransomware Affiliate
- Microsoft Warns of New INC Ransomware Targeting U.S. Healthcare Sector
- Vanilla Tempest's Ransomware Tactics: Gootloader to INC Payload
More in malware
- PowerShell Cryptomining Loader Abuses Registry-Resident Scripts, DNS TXT Records, and PNG/WAV Steganography for Stealth C2
- RatHat: AI-Powered Android Banking Trojan Abuses Accessibility Service and ADB to Steal Credentials, PINs, and MFA Codes
- FomoPeek iOS App Store Poisoning: Kernel Exploit Framework Steals Crypto Private Keys via Keychain Decryption
- ClearFake Drive-By Cluster Fuels CastleLoader Paste-and-Run Delivery of NetSupport RAT, CastleRAT, and a .NET Stealer
- MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana Blockchain for C2
Detection coverage for TL-2026-2199
As of 2026-08-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2199 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.