ClickFix Cluster Uses DLL Sideloading and Compromised WordPress Sites to Deliver Lorem Ipsum Loader, Linked to Vanilla Tempest — Threadlinqs Intelligence
As of 2026-08-29, ClickFix Cluster Uses DLL Sideloading and Compromised WordPress Sites to Deliver Lorem Ipsum Loader, Linked to Vanilla Tempest is a high-severity malware threat attributed to Vanilla Tempest, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 33 indicators of compromise.
Threat ID: TL-2026-2199 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Vanilla Tempest · FINANCIAL
Field Effect tracked three distinct ClickFix social-engineering campaigns (June-July 2026) that share file-naming conventions, DLL sideloading via renamed legitimate binaries, and command-and-control
Field Effect's 2026-08-24 report documents a ClickFix cluster comprising three distinct campaigns observed between mid-June and July 2026, unified by shared naming conventions, a common DLL-sideloading pattern, and a shared command-and-control (C2) dead-drop resolver hosted on the digitalpoint.com forum. Campaign 1 (mid-June 2026) delivered remotely hosted MSI packages via a ClickFix clipboard prompt invoking `MsieXEc.ExE /pAckAGe`, abusing legitimate installers for 3D PDF Maker Smart, Bitwarden VPN, and ESET SysInspector to sideload a malicious mscoree.dll alongside a renamed copy of Microsoft's ClickOnce Launch Utility (masquerading as 'NET Runtime Optimization Service.exe'). Persistence was established via a scheduled task, a hidden ProgramData subfolder was created with attrib.exe (+h +s), and PowerShell executed dsregcmd.exe /status for host discovery; Field Effect documented an approximately six-day dwell time before loader deployment. Campaign 2 (late June 2026) shared Campaign 1's infrastructure and mscoree.dll/ClickOnce sideload chain but delivered payloads via PowerShell downloading and executing an outdated NodeJS v7.10.1 runtime alongside a malicious update.js. Campaign 3 (July 2026) used a compromised WordPress site serving JavaScript from /js/all.min.js that performed Polygon-blockchain-based C2 domain retrieval, fingerprinted the victim (RAM, CPU, browser language/user agent), and served a localized ClickFix lure leading to an embedded Python 3.5 install, an obfuscated Captcha.py payload, and DLL sideloading via LockScreenContentServer.exe; persistence used a Run registry key plus an hourly scheduled task, with second-stage infrastructure hosted at cooldogshistory.com. Across all three campaigns, post-compromise activity included Active Directory and host-discovery commands (nltest.exe /dclist:, net.exe group "domain admins" /domain, nltest /domain_trusts, ipconfig.exe, net.exe user <user> /domain, net.exe localgroup administrators) and an ADSI-searcher PowerShell query for user accounts with populated description fields. C2 used a dead-drop resolver technique on digitalpoint.com forum member profiles (digitalpoint.com/members/trytodetectme.1134520, digitalpoint.com/members/documentpublisher.1139897), where encoded, space-delimited strings in the profile info tab decode to live C2 domains; victims subsequently POST JFIF-disguised uploads to /api/init/<guid>. Prior reporting on this same dead-drop technique (tracked by BlueVoyant against the Lorem Ipsum loader) documents the resolver platform migrating from letsdiskuss.com to digitalpoint.com after public disclosure, while retaining the '-=(' / ')=-' delimiter convention, substitution-cipher decoding, one-profile-to-one-C2-cluster mapping, and per-victim beaconing to three redundant Cloudflare-fronted C2 domains. Field Effect ties this cluster to BlueVoyant's Lorem Ipsum loader family, active since February 2026 and originally delivered via trojanized, fraudulently code-signed Microsoft Teams installers before pivoting to ClickFix after Microsoft disrupted the malware-signing service the operators relied on. BlueVoyant and other reporting attribute Lorem Ipsum/ClickFix activity to Rapid Brigantine, also tracked as Vanilla Tempest, DEV-0832, Vice Society, and Vice Spider, and describe Lorem Ipsum's DLL side-loading chains (observed using both mscoree.dll and msvcp140.dll variants) as leading to ransomware deployment (Rhysida, BlackCat, Zeppelin, Quantum Locker in BlueVoyant's broader Lorem Ipsum tracking). Independently, Microsoft has attributed the Active Directory/domain-trust enumeration TTPs and the Supper backdoor specifically to Vanilla Tempest, a financially motivated actor that receives handoffs from Storm-0494 (Gootloader) intrusions and has deployed INC ransomware against U.S. healthcare targets, using AnyDesk, MEGA, RDP, and WMI for lateral movement and exfiltration ahead of ransomware detonation. Field Effect's cluster does not itself confirm ransomwar
Target sectors: architecture, legal services, construction technology, health, education, it
Timeline
- BlueVoyant tracks the Lorem Ipsum loader campaign beginning, initially delivered via trojanized Microsoft Teams installers using fraudulently obtained code-signing certificates.
- Microsoft disrupts the malware-signing-as-a-service operation the Lorem Ipsum operators relied on for signed installers, forcing a pivot from trojanized installers to ClickFix-based delivery.
- Field Effect observes Campaign 1: ClickFix clipboard prompts invoking msiexec.exe to fetch remote MSI packages abusing 3D PDF Maker Smart, Bitwarden VPN, and ESET SysInspector to sideload mscoree.dll via a renamed ClickOnce Launch Utility.
- Field Effect documents an approximately six-day dwell time in Campaign 1 intrusions between initial MSI-based compromise and loader deployment, with a hidden ProgramData subfolder created via attrib.exe (+h +s).
- Field Effect observes Campaign 2, sharing Campaign 1's infrastructure: PowerShell downloads an outdated NodeJS v7.10.1 runtime and executes a malicious update.js alongside the same mscoree.dll sideload chain.
- Field Effect observes Campaign 3: a compromised WordPress site serves JavaScript (/js/all.min.js) using Polygon blockchain-based C2 domain retrieval, victim fingerprinting, and a localized ClickFix lure leading to an embedded Python 3.5 install, obfuscated Captcha.py, and LockScreenContentServer.exe DLL sideloading with Run-key and hourly-scheduled-task persistence.
- Field Effect publishes 'A ClickFix cluster,' correlating all three campaigns via shared naming conventions, DLL sideloading, and digitalpoint.com dead-drop C2, and links the cluster to BlueVoyant's Lorem Ipsum loader and, via the Supper backdoor, to Vanilla Tempest.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 33 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1681, T1583.006, T1204.004, T1218.007, T1059.003, T1059.007, T1059.006, T1574.001, T1053.005, T1547.001