Threat reportMalwareTL-2026-2995
TerminalFix ClickFix lure and Lorem Ipsum Loader deliver covert Python WebSocket tunneling implant (STAC4924)
TerminalFix ClickFix lure and Lorem Ipsum Loader deliver (TL-2026-2995), also tracked as STAC4924, is a high-severity malware campaign, first published 2026-10-07. It is attributed to GOLD VICTOR with medium confidence, affects Microsoft Windows (endpoints; Windows Terminal, PowerShell, sideloaded, maps to 18 MITRE ATT&CK techniques (T1001.002, T1027, T1027.003), and is covered by 9 detection rules and 30 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 18MITRE ATT&CK
- Actors
- 3GOLD VICTOR
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 30Indicators of compromise
Key facts for TL-2026-2995
- Threat ID
- TL-2026-2995
- Also known as
- STAC4924, TerminalFix, Lorem Ipsum Loader
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- GOLD VICTOR, Vanilla Tempest, Rapid Brigantine
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Detection rules
- 9
- Indicators of compromise
- 30
Malware and tooling in TerminalFix ClickFix lure and Lorem Ipsum Loader deliver
Malware and tooling: ATK/PyTune-B, Lorem Ipsum Loader, rhysida
How TerminalFix ClickFix lure and Lorem Ipsum Loader deliver works
Sophos tracks STAC4924, a campaign that evolved from trojanized Microsoft Teams MSI installers into TerminalFix, a ClickFix variant telling victims to open Windows Terminal and paste a PowerShell command. The chain downloads a ZIP, sideloads Lorem Ipsum Loader through a legitimate Windows binary, and installs a Python encrypted-WebSocket tunneling implant. Sophos links it with moderate confidence to GOLD VICTOR (Vanilla Tempest / Rapid Brigantine), a Vice Society and Rhysida ransomware-associated group.
In August 2026 Sophos analysts began investigating Managed Detection and Response cases involving ClickFix-style lures that ended in a Python-based tunneling implant. Sophos tracks the activity as STAC4924. TerminalFix differs from classic ClickFix in that the lure tells the victim to open a Windows Terminal window rather than the Run dialog; Sophos states TerminalFix itself is not tied to one threat group or campaign.
By following the lure the victim runs a PowerShell command that downloads a ZIP archive containing a legitimate Windows executable, a malicious DLL and a batch script. The command runs the batch script, which installs several persistence mechanisms (scheduled tasks and auto-run registry entries masquerading as Microsoft or software-update components) and launches the legitimate binary, for example LockScreenContentServer.exe. That binary sideloads the malicious dui70.dll. Sophos observed many sideloading pairs, including changepk.exe with slc.dll/faultrep.dll/sppcext.dll, werfaultsecure.exe with faultrep.dll, certenrollctrl.exe with certenroll.dll, vdsldr.exe with vdsutil.dll, wlrmdr.exe, phoneactivate.exe and sessionmsg.exe with dui70.dll/duser.dll, and executables named like .NET, Edge Updates and Teams helpers sideloading mscoree.dll or msvcp140.dll.
The DLL is Lorem Ipsum Loader, a shellcode loader first observed by BlueVoyant. It stores shellcode as English words plus hexadecimal mapping tables to evade entropy-based detection. It queries attacker-controlled profiles on the legitimate Letsdiskuss platform as a dead-drop resolver to obtain the C2 server list, then communicates by HTTP POST requests disguised as JPEG image transfers carrying encoded data. The final stage is a Python tunneling implant (client.py) deployed to Users\Public\indigo using the embedded Python package from python.org. It opens encrypted WebSocket connections to attacker infrastructure, assigns each host a unique UUID, and relays arbitrary traffic through the compromised endpoint. PowerShell-based Active Directory reconnaissance was also observed.
Sophos describes two phases. Phase 1 (March-April 2026) used SEO-poisoned sites distributing trojanized Microsoft Teams MSI installers, multi-stage PowerShell loaders and Letsdiskuss dead-drop resolvers. Phase 2 (late May through September 2026) moved to TerminalFix lures, DLL sideloading, image steganography and the Python reverse-tunnel implant, following Microsoft's takedown of a malware-signing service. BlueVoyant, which attributes Lorem Ipsum to Rapid Brigantine, dates the Microsoft disruption of Fox Tempest / Forging Marauder to 19 May 2026. Sophos links both phases to GOLD VICTOR (Vanilla Tempest, DEV-0832, VICE SPIDER, Vice Society) with moderate confidence, based on per-victim UUID callback structure, repeated use of the Letsdiskuss dead-drop, evolving sideloading tradecraft and persistence that mimics legitimate software. No encryption (ransomware) activity was observed in STAC4924, but BlueVoyant describes Lorem Ipsum as handing off to Rapid Brigantine's post-exploitation tooling and ultimately Rhysida ransomware. The Sophos report does not name targeted sectors or regions.
MITRE ATT&CK techniques used in TL-2026-2995
Command and Control
T1001.002 Steganography; T1071.001 Web Protocols; T1090 Proxy; T1102.001 Dead Drop Resolver; T1572 Protocol Tunneling; T1573 Encrypted Channel
Stealth
T1027 Obfuscated Files or Information; T1027.003 Steganography; T1036.005 Match Legitimate Resource Name or Location; T1574.001 DLL
Persistence
T1053.005 Scheduled Task; T1547.001 Registry Run Keys / Startup Folder
Execution
T1059.001 PowerShell; T1059.003 Windows Command Shell; T1204.002 Malicious File; T1204.004 Malicious Copy and Paste
Discovery
execution
T1204.004 Malicious Copy and Paste
stealth
Resource Development
Affected products and versions in TerminalFix ClickFix lure and Lorem Ipsum Loader deliver
- Microsoft — Windows (endpoints; Windows Terminal, PowerShell, sideloaded legitimate Windows binaries)
Remediation for TerminalFix ClickFix lure and Lorem Ipsum Loader deliver
Immediate actions
- Block and alert on the STAC4924 C2, staging and dead-drop indicators (STAC4924_IOCs.csv in the SophosLabs IoCs GitHub repository)
- Hunt for powershell.exe launched from Windows Terminal that downloads a ZIP and runs a batch script
- Hunt for LockScreenContentServer.exe and other sideloading pairs (e.g. dui70.dll) running from user-writable paths, and for Users\Public\indigo containing client.py and a python.org embedded Python runtime
- Review scheduled tasks and Run keys named like Microsoft or software-update components
Workarounds
- Application control (WDAC/AppLocker) rules blocking execution of binaries and DLLs from %PUBLIC% and user-writable directories
Longer-term hardening
- Train staff to recognize ClickFix-style lures, including instructions to open Windows Terminal or paste commands
- Restrict or monitor paste-and-run PowerShell and Windows Terminal use on non-admin endpoints
- Monitor HTTP POST traffic to rare domains claiming to be JPEG images and long-lived WebSocket connections from non-browser processes
- Monitor outbound requests to Letsdiskuss user profiles from non-browser processes
Timeline of TerminalFix ClickFix lure and Lorem Ipsum Loader deliver
- BlueVoyant first observes Lorem Ipsum Loader (per Sophos, February 2026; exact day not stated)
- Sophos assesses the broader campaign has been active since at least March 2026, using SEO-poisoned sites serving trojanized Microsoft Teams MSI installers, multi-stage PowerShell loaders and Letsdiskuss dead-drop resolvers (phase 1, March-April; exact day not stated)
- Microsoft disrupts Fox Tempest / Forging Marauder, a malware-signing-as-a-service operation; BlueVoyant ties the end of signed-installer delivery to this date and the pivot to ClickFix
- Phase 2 begins in late May 2026 (exact day not stated): operators move to TerminalFix lures, DLL sideloading, image steganography and a Python reverse-tunnel implant
- BlueVoyant publishes 'Lorem Ipsum Revisited', describing the ClickFix pivot on compromised WordPress sites and attributing the loader to Rapid Brigantine
- Sophos analysts begin investigating MDR cases involving ClickFix-style lures that deploy a Python-based tunneling implant (August 2026; exact day not stated); activity continues through September
- Malpedia library entry for the Sophos report is added, linking family win.lorem_ipsum
Sources cited for TerminalFix ClickFix lure and Lorem Ipsum Loader deliver
- TerminalFix and Lorem Ipsum Loader enable covert tunneling (Sophos Counter Threat Unit)
- Sophos STAC4924 IOCs (STAC4924_IOCs.csv)
- Malpedia library entry: TerminalFix and Lorem Ipsum Loader enable covert tunneling
- Lorem Ipsum Revisited: A ClickFix Pivot & Its Rapid Brigantine Lineage (BlueVoyant)
- Lorem Ipsum Malware: Trojanized MS Teams Installers, Multi-Stage Loader and Backdoor (BlueVoyant)
- ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures (The Hacker News)
- 'Lorem Ipsum' Malware Pivots to ClickFix Delivery (Dark Reading)
- TerminalFix Campaign Uses PowerShell and DLL Sideloading to Establish Covert C2 Tunnels (Cyber Press)
Detection coverage for TL-2026-2995
As of 2026-10-07, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2995 across Splunk SPL, Microsoft KQL and Sigma, covering 30 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.