TerminalFix Lures and Lorem Ipsum Loader Deploy a Covert Tunneling Implant

· Original article ↗

Summary

Sophos details STAC4924, a campaign using TerminalFix lures and Lorem Ipsum Loader to install a Python-based reverse-tunneling implant, following an earlier phase that distributed trojanized Teams installers.

Key points

  • TerminalFix lures direct victims to run a PowerShell command in Windows Terminal, which downloads a ZIP archive containing a legitimate executable, a malicious DLL, and a batch script.
  • DLL sideloading launches Lorem Ipsum Loader, which retrieves C2 server details from an attacker-controlled profile on Letsdiskuss and disguises C2 traffic as JPEG image transfers.
  • The loader deploys a portable Python runtime and custom implant that establishes an encrypted WebSocket tunnel, allowing attackers to relay traffic through compromised hosts and reach network resources.
  • STAC4924's March–April phase used SEO-poisoned sites to distribute trojanized Microsoft Teams MSI installers; from late May, activity shifted to TerminalFix lures.
  • Sophos assesses with moderate confidence that both phases involve the same or closely associated threat actors, based on shared infrastructure and techniques.
  • BlueVoyant attributed Lorem Ipsum Loader to GOLD VICTOR, also known as Vanilla Tempest and Vice Society; Sophos has not observed encryption in this campaign.
  • Sophos recommends monitoring for infection, remediating affected systems, and training employees to recognize ClickFix-style lures.

Article Details

Attack Vectors
  • TerminalFix lures instructed victims to open Windows Terminal and run a PowerShell command that downloaded a ZIP archive and executed its batch script.
  • In the earlier phase, SEO-poisoned websites distributed trojanized Microsoft Teams MSI installers.
  • A legitimate executable loaded a malicious DLL through DLL sideloading to execute Lorem Ipsum Loader.
  • Lorem Ipsum Loader retrieved C2 server information from an attacker-controlled profile on Letsdiskuss and exchanged encoded data with C2 servers in HTTP requests resembling JPEG image transfers.
  • A custom Python implant established an encrypted WebSocket tunnel that let the threat actors relay traffic through compromised hosts.
  • Auto-run entries masquerading as legitimate components, sometimes reinforced by scheduled tasks, provided persistence.
Defensive Notes
  • Monitor environments for evidence of infection and remediate affected systems to limit impact.
  • Train employees to recognize ClickFix-style lures, including instructions to run commands in Windows Terminal.

MITRE ATT&CK

T1001.002 · SteganographyC2 exchanges appeared to contain JPEG files, but the images held encoded data that the malware extracted and decoded.T1027 · Obfuscated Files or InformationLorem Ipsum Loader stored shellcode bytes as English words and used a lookup table to decode them, attempting to evade entropy-based detection.T1036 · MasqueradingPersistence entries masqueraded as legitimate Microsoft or software-update components.T1053.005 · Scheduled TaskScheduled tasks sometimes reinforced the campaign's persistence mechanisms.T1059.001 · PowerShellTerminalFix victims ran a PowerShell download command; the malware later executed PowerShell commands for reconnaissance, information gathering, and persistence.T1071.001 · Web ProtocolsThe loader communicated with C2 servers using HTTP POST requests, and the tunneling implant connected over WebSocket.T1102.001 · Dead Drop ResolverThe loader used an attacker-controlled Letsdiskuss profile as a dead-drop resolver for its current C2 servers.T1105 · Ingress Tool TransferThe initial PowerShell command downloaded a ZIP archive, and the malware later downloaded a Python embedded package to support the tunneling implant.T1547.001 · Registry Run Keys / Startup FolderThe intrusions established persistence through auto-run entries masquerading as legitimate Microsoft or software-update components.T1572 · Protocol TunnelingThe Python implant established an encrypted WebSocket tunnel to attacker-controlled servers, enabling traffic relay through the compromised host.T1574.002 · DLL Side-LoadingLegitimate executables, including LockScreenContentServer.exe, loaded malicious paired DLLs through DLL sideloading.

Threat Actors

Malware

Vendors

Products

Related Articles