# TerminalFix ClickFix lure and Lorem Ipsum Loader deliver covert Python WebSocket tunneling implant (STAC4924)

> Sophos tracks STAC4924, a campaign that evolved from trojanized Microsoft Teams MSI installers into TerminalFix, a ClickFix variant telling victims to open Windows Terminal and paste a PowerShell command. The chain downloads a ZIP, sideloads Lorem Ipsum Loader through a legitimate Windows binary, and installs a Python encrypted-WebSocket tunneling implant. Sophos links it with moderate confidence to GOLD VICTOR (Vanilla Tempest / Rapid Brigantine), a Vice Society and Rhysida ransomware-associated group.

- **Published:** 2026-10-07T00:00:00Z
- **Last reviewed:** 2026-10-07T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2995
- **ID:** TL-2026-2995
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** GOLD VICTOR
- **Detections:** 9 · **IOCs:** 30 (full data via the Threadlinqs MCP server — Purple tier)

## Description

In August 2026 Sophos analysts began investigating Managed Detection and Response cases involving ClickFix-style lures that ended in a Python-based tunneling implant. Sophos tracks the activity as STAC4924. TerminalFix differs from classic ClickFix in that the lure tells the victim to open a Windows Terminal window rather than the Run dialog; Sophos states TerminalFix itself is not tied to one threat group or campaign.

By following the lure the victim runs a PowerShell command that downloads a ZIP archive containing a legitimate Windows executable, a malicious DLL and a batch script. The command runs the batch script, which installs several persistence mechanisms (scheduled tasks and auto-run registry entries masquerading as Microsoft or software-update components) and launches the legitimate binary, for example LockScreenContentServer.exe. That binary sideloads the malicious dui70.dll. Sophos observed many sideloading pairs, including changepk.exe with slc.dll/faultrep.dll/sppcext.dll, werfaultsecure.exe with faultrep.dll, certenrollctrl.exe with certenroll.dll, vdsldr.exe with vdsutil.dll, wlrmdr.exe, phoneactivate.exe and sessionmsg.exe with dui70.dll/duser.dll, and executables named like .NET, Edge Updates and Teams helpers sideloading mscoree.dll or msvcp140.dll.

The DLL is Lorem Ipsum Loader, a shellcode loader first observed by BlueVoyant. It stores shellcode as English words plus hexadecimal mapping tables to evade entropy-based detection. It queries attacker-controlled profiles on the legitimate Letsdiskuss platform as a dead-drop resolver to obtain the C2 server list, then communicates by HTTP POST requests disguised as JPEG image transfers carrying encoded data. The final stage is a Python tunneling implant (client.py) deployed to Users\Public\indigo using the embedded Python package from python.org. It opens encrypted WebSocket connections to attacker infrastructure, assigns each host a unique UUID, and relays arbitrary traffic through the compromised endpoint. PowerShell-based Active Directory reconnaissance was also observed.

Sophos describes two phases. Phase 1 (March-April 2026) used SEO-poisoned sites distributing trojanized Microsoft Teams MSI installers, multi-stage PowerShell loaders and Letsdiskuss dead-drop resolvers. Phase 2 (late May through September 2026) moved to TerminalFix lures, DLL sideloading, image steganography and the Python reverse-tunnel implant, following Microsoft's takedown of a malware-signing service. BlueVoyant, which attributes Lorem Ipsum to Rapid Brigantine, dates the Microsoft disruption of Fox Tempest / Forging Marauder to 19 May 2026. Sophos links both phases to GOLD VICTOR (Vanilla Tempest, DEV-0832, VICE SPIDER, Vice Society) with moderate confidence, based on per-victim UUID callback structure, repeated use of the Letsdiskuss dead-drop, evolving sideloading tradecraft and persistence that mimics legitimate software. No encryption (ransomware) activity was observed in STAC4924, but BlueVoyant describes Lorem Ipsum as handing off to Rapid Brigantine's post-exploitation tooling and ultimately Rhysida ransomware. The Sophos report does not name targeted sectors or regions.

## MITRE ATT&CK

- T1204.004 Malicious Copy and Paste
- T1204.004 Malicious Copy and Paste
- T1204.002 Malicious File
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1608.006 SEO Poisoning
- T1053.005 Scheduled Task
- T1547.001 Registry Run Keys / Startup Folder
- T1574.001 DLL
- T1574.001 DLL
- T1036.005 Match Legitimate Resource Name or Location
- T1027 Obfuscated Files or Information
- T1027.003 Steganography
- T1087.002 Domain Account
- T1102.001 Dead Drop Resolver
- T1071.001 Web Protocols
- T1001.002 Steganography
- T1572 Protocol Tunneling
- T1573 Encrypted Channel
- T1090 Proxy

## Sources

- [TerminalFix and Lorem Ipsum Loader enable covert tunneling (Sophos Counter Threat Unit)](https://www.sophos.com/blog/terminalfix-and-lorem-ipsum-loader-enable-covert-tunneling)
- [Sophos STAC4924 IOCs (STAC4924_IOCs.csv)](https://github.com/sophoslabs/IoCs/blob/master/STAC4924_IOCs.csv)
- [Malpedia library entry: TerminalFix and Lorem Ipsum Loader enable covert tunneling](https://malpedia.caad.fkie.fraunhofer.de/library/ecfb6c35-ffd9-44e6-8698-43f019a06cdd/)
- [Lorem Ipsum Revisited: A ClickFix Pivot & Its Rapid Brigantine Lineage (BlueVoyant)](https://www.bluevoyant.com/blog/orem-ipsum-clickfix-rapid-brigantine)
- [Lorem Ipsum Malware: Trojanized MS Teams Installers, Multi-Stage Loader and Backdoor (BlueVoyant)](https://www.bluevoyant.com/blog/lorem-ipsum-trojanized-microsoft-teams-installers-multi-stage-loader-backdoor)
- [ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures (The Hacker News)](https://thehackernews.com/2026/06/clickfix-campaigns-expand-malware.html)
- ['Lorem Ipsum' Malware Pivots to ClickFix Delivery (Dark Reading)](https://www.darkreading.com/cyberattacks-data-breaches/lorem-ipsum-malware-clickfix-delivery)
- [TerminalFix Campaign Uses PowerShell and DLL Sideloading to Establish Covert C2 Tunnels (Cyber Press)](https://cyberpress.org/terminalfix-campaign-uses-powershell/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2995
