Threat reportMalwareTL-2026-2995

TerminalFix ClickFix lure and Lorem Ipsum Loader deliver covert Python WebSocket tunneling implant (STAC4924)

highACTIVE

TerminalFix ClickFix lure and Lorem Ipsum Loader deliver (TL-2026-2995), also tracked as STAC4924, is a high-severity malware campaign, first published 2026-10-07. It is attributed to GOLD VICTOR with medium confidence, affects Microsoft Windows (endpoints; Windows Terminal, PowerShell, sideloaded, maps to 18 MITRE ATT&CK techniques (T1001.002, T1027, T1027.003), and is covered by 9 detection rules and 30 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
18MITRE ATT&CK
Actors
3GOLD VICTOR
Detection rules
9SPL · KQL · Sigma
IOCs
30Indicators of compromise

Key facts for TL-2026-2995

Threat ID
TL-2026-2995
Also known as
STAC4924, TerminalFix, Lorem Ipsum Loader
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
GOLD VICTOR, Vanilla Tempest, Rapid Brigantine
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Detection rules
9
Indicators of compromise
30

Malware and tooling in TerminalFix ClickFix lure and Lorem Ipsum Loader deliver

Malware and tooling: ATK/PyTune-B, Lorem Ipsum Loader, rhysida

How TerminalFix ClickFix lure and Lorem Ipsum Loader deliver works

Sophos tracks STAC4924, a campaign that evolved from trojanized Microsoft Teams MSI installers into TerminalFix, a ClickFix variant telling victims to open Windows Terminal and paste a PowerShell command. The chain downloads a ZIP, sideloads Lorem Ipsum Loader through a legitimate Windows binary, and installs a Python encrypted-WebSocket tunneling implant. Sophos links it with moderate confidence to GOLD VICTOR (Vanilla Tempest / Rapid Brigantine), a Vice Society and Rhysida ransomware-associated group.

In August 2026 Sophos analysts began investigating Managed Detection and Response cases involving ClickFix-style lures that ended in a Python-based tunneling implant. Sophos tracks the activity as STAC4924. TerminalFix differs from classic ClickFix in that the lure tells the victim to open a Windows Terminal window rather than the Run dialog; Sophos states TerminalFix itself is not tied to one threat group or campaign.

By following the lure the victim runs a PowerShell command that downloads a ZIP archive containing a legitimate Windows executable, a malicious DLL and a batch script. The command runs the batch script, which installs several persistence mechanisms (scheduled tasks and auto-run registry entries masquerading as Microsoft or software-update components) and launches the legitimate binary, for example LockScreenContentServer.exe. That binary sideloads the malicious dui70.dll. Sophos observed many sideloading pairs, including changepk.exe with slc.dll/faultrep.dll/sppcext.dll, werfaultsecure.exe with faultrep.dll, certenrollctrl.exe with certenroll.dll, vdsldr.exe with vdsutil.dll, wlrmdr.exe, phoneactivate.exe and sessionmsg.exe with dui70.dll/duser.dll, and executables named like .NET, Edge Updates and Teams helpers sideloading mscoree.dll or msvcp140.dll.

The DLL is Lorem Ipsum Loader, a shellcode loader first observed by BlueVoyant. It stores shellcode as English words plus hexadecimal mapping tables to evade entropy-based detection. It queries attacker-controlled profiles on the legitimate Letsdiskuss platform as a dead-drop resolver to obtain the C2 server list, then communicates by HTTP POST requests disguised as JPEG image transfers carrying encoded data. The final stage is a Python tunneling implant (client.py) deployed to Users\Public\indigo using the embedded Python package from python.org. It opens encrypted WebSocket connections to attacker infrastructure, assigns each host a unique UUID, and relays arbitrary traffic through the compromised endpoint. PowerShell-based Active Directory reconnaissance was also observed.

Sophos describes two phases. Phase 1 (March-April 2026) used SEO-poisoned sites distributing trojanized Microsoft Teams MSI installers, multi-stage PowerShell loaders and Letsdiskuss dead-drop resolvers. Phase 2 (late May through September 2026) moved to TerminalFix lures, DLL sideloading, image steganography and the Python reverse-tunnel implant, following Microsoft's takedown of a malware-signing service. BlueVoyant, which attributes Lorem Ipsum to Rapid Brigantine, dates the Microsoft disruption of Fox Tempest / Forging Marauder to 19 May 2026. Sophos links both phases to GOLD VICTOR (Vanilla Tempest, DEV-0832, VICE SPIDER, Vice Society) with moderate confidence, based on per-victim UUID callback structure, repeated use of the Letsdiskuss dead-drop, evolving sideloading tradecraft and persistence that mimics legitimate software. No encryption (ransomware) activity was observed in STAC4924, but BlueVoyant describes Lorem Ipsum as handing off to Rapid Brigantine's post-exploitation tooling and ultimately Rhysida ransomware. The Sophos report does not name targeted sectors or regions.

MITRE ATT&CK techniques used in TL-2026-2995

Command and Control

T1001.002 Steganography; T1071.001 Web Protocols; T1090 Proxy; T1102.001 Dead Drop Resolver; T1572 Protocol Tunneling; T1573 Encrypted Channel

Stealth

T1027 Obfuscated Files or Information; T1027.003 Steganography; T1036.005 Match Legitimate Resource Name or Location; T1574.001 DLL

Persistence

T1053.005 Scheduled Task; T1547.001 Registry Run Keys / Startup Folder

Execution

T1059.001 PowerShell; T1059.003 Windows Command Shell; T1204.002 Malicious File; T1204.004 Malicious Copy and Paste

Discovery

T1087.002 Domain Account

execution

T1204.004 Malicious Copy and Paste

stealth

T1574.001 DLL

Resource Development

T1608.006 SEO Poisoning

Affected products and versions in TerminalFix ClickFix lure and Lorem Ipsum Loader deliver

  • Microsoft — Windows (endpoints; Windows Terminal, PowerShell, sideloaded legitimate Windows binaries)

Remediation for TerminalFix ClickFix lure and Lorem Ipsum Loader deliver

Immediate actions

  • Block and alert on the STAC4924 C2, staging and dead-drop indicators (STAC4924_IOCs.csv in the SophosLabs IoCs GitHub repository)
  • Hunt for powershell.exe launched from Windows Terminal that downloads a ZIP and runs a batch script
  • Hunt for LockScreenContentServer.exe and other sideloading pairs (e.g. dui70.dll) running from user-writable paths, and for Users\Public\indigo containing client.py and a python.org embedded Python runtime
  • Review scheduled tasks and Run keys named like Microsoft or software-update components

Workarounds

  • Application control (WDAC/AppLocker) rules blocking execution of binaries and DLLs from %PUBLIC% and user-writable directories

Longer-term hardening

  • Train staff to recognize ClickFix-style lures, including instructions to open Windows Terminal or paste commands
  • Restrict or monitor paste-and-run PowerShell and Windows Terminal use on non-admin endpoints
  • Monitor HTTP POST traffic to rare domains claiming to be JPEG images and long-lived WebSocket connections from non-browser processes
  • Monitor outbound requests to Letsdiskuss user profiles from non-browser processes

Timeline of TerminalFix ClickFix lure and Lorem Ipsum Loader deliver

  • BlueVoyant first observes Lorem Ipsum Loader (per Sophos, February 2026; exact day not stated)
  • Sophos assesses the broader campaign has been active since at least March 2026, using SEO-poisoned sites serving trojanized Microsoft Teams MSI installers, multi-stage PowerShell loaders and Letsdiskuss dead-drop resolvers (phase 1, March-April; exact day not stated)
  • Microsoft disrupts Fox Tempest / Forging Marauder, a malware-signing-as-a-service operation; BlueVoyant ties the end of signed-installer delivery to this date and the pivot to ClickFix
  • Phase 2 begins in late May 2026 (exact day not stated): operators move to TerminalFix lures, DLL sideloading, image steganography and a Python reverse-tunnel implant
  • BlueVoyant publishes 'Lorem Ipsum Revisited', describing the ClickFix pivot on compromised WordPress sites and attributing the loader to Rapid Brigantine
  • Sophos analysts begin investigating MDR cases involving ClickFix-style lures that deploy a Python-based tunneling implant (August 2026; exact day not stated); activity continues through September
  • Malpedia library entry for the Sophos report is added, linking family win.lorem_ipsum

Sources cited for TerminalFix ClickFix lure and Lorem Ipsum Loader deliver

Detection coverage for TL-2026-2995

As of 2026-10-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2995 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
30 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats