TerminalFix Lures and Lorem Ipsum Loader Deploy a Covert Tunneling Implant

Summary
Sophos details STAC4924, a campaign using TerminalFix lures and Lorem Ipsum Loader to install a Python-based reverse-tunneling implant, following an earlier phase that distributed trojanized Teams installers.
Key points
- TerminalFix lures direct victims to run a PowerShell command in Windows Terminal, which downloads a ZIP archive containing a legitimate executable, a malicious DLL, and a batch script.
- DLL sideloading launches Lorem Ipsum Loader, which retrieves C2 server details from an attacker-controlled profile on Letsdiskuss and disguises C2 traffic as JPEG image transfers.
- The loader deploys a portable Python runtime and custom implant that establishes an encrypted WebSocket tunnel, allowing attackers to relay traffic through compromised hosts and reach network resources.
- STAC4924's March–April phase used SEO-poisoned sites to distribute trojanized Microsoft Teams MSI installers; from late May, activity shifted to TerminalFix lures.
- Sophos assesses with moderate confidence that both phases involve the same or closely associated threat actors, based on shared infrastructure and techniques.
- BlueVoyant attributed Lorem Ipsum Loader to GOLD VICTOR, also known as Vanilla Tempest and Vice Society; Sophos has not observed encryption in this campaign.
- Sophos recommends monitoring for infection, remediating affected systems, and training employees to recognize ClickFix-style lures.
Article Details
- Attack Vectors
- TerminalFix lures instructed victims to open Windows Terminal and run a PowerShell command that downloaded a ZIP archive and executed its batch script.
- In the earlier phase, SEO-poisoned websites distributed trojanized Microsoft Teams MSI installers.
- A legitimate executable loaded a malicious DLL through DLL sideloading to execute Lorem Ipsum Loader.
- Lorem Ipsum Loader retrieved C2 server information from an attacker-controlled profile on Letsdiskuss and exchanged encoded data with C2 servers in HTTP requests resembling JPEG image transfers.
- A custom Python implant established an encrypted WebSocket tunnel that let the threat actors relay traffic through compromised hosts.
- Auto-run entries masquerading as legitimate components, sometimes reinforced by scheduled tasks, provided persistence.
- Defensive Notes
- Monitor environments for evidence of infection and remediate affected systems to limit impact.
- Train employees to recognize ClickFix-style lures, including instructions to run commands in Windows Terminal.
MITRE ATT&CK
T1001.002 · SteganographyC2 exchanges appeared to contain JPEG files, but the images held encoded data that the malware extracted and decoded.T1027 · Obfuscated Files or InformationLorem Ipsum Loader stored shellcode bytes as English words and used a lookup table to decode them, attempting to evade entropy-based detection.T1036 · MasqueradingPersistence entries masqueraded as legitimate Microsoft or software-update components.T1053.005 · Scheduled TaskScheduled tasks sometimes reinforced the campaign's persistence mechanisms.T1059.001 · PowerShellTerminalFix victims ran a PowerShell download command; the malware later executed PowerShell commands for reconnaissance, information gathering, and persistence.T1071.001 · Web ProtocolsThe loader communicated with C2 servers using HTTP POST requests, and the tunneling implant connected over WebSocket.T1102.001 · Dead Drop ResolverThe loader used an attacker-controlled Letsdiskuss profile as a dead-drop resolver for its current C2 servers.T1105 · Ingress Tool TransferThe initial PowerShell command downloaded a ZIP archive, and the malware later downloaded a Python embedded package to support the tunneling implant.T1547.001 · Registry Run Keys / Startup FolderThe intrusions established persistence through auto-run entries masquerading as legitimate Microsoft or software-update components.T1572 · Protocol TunnelingThe Python implant established an encrypted WebSocket tunnel to attacker-controlled servers, enabling traffic relay through the compromised host.T1574.002 · DLL Side-LoadingLegitimate executables, including LockScreenContentServer.exe, loaded malicious paired DLLs through DLL sideloading.
Threat Actors
DEV-0832Listed as another name for GOLD VICTOR, the group Sophos Counter Threat Unit tracks as Rapid Brigantine.GOLD VICTORSophos Counter Threat Unit tracks Rapid Brigantine as GOLD VICTOR.Rapid BrigantineBlueVoyant attributed Lorem Ipsum Loader to this cybercriminal group; Sophos said the observed STAC4924 tooling and infrastructure supported that attribution.Vanilla TempestListed as another name for GOLD VICTOR, the group Sophos Counter Threat Unit tracks as Rapid Brigantine.Vice SocietyListed as another name for GOLD VICTOR, the group Sophos Counter Threat Unit tracks as Rapid Brigantine.VICE SPIDERListed as another name for GOLD VICTOR, the group Sophos Counter Threat Unit tracks as Rapid Brigantine.
Malware
Lorem Ipsum LoaderWhile investigating this activity, Sophos analysts identified the deployment of Lorem Ipsum Loader, a shellcode-based loader first observed by BlueVoyant in February 2026. The presence of this malware, combined with theRhysidaTempest, DEV-0832, VICE SPIDER, and Vice Society). This group has been linked to the Vice Society and Rhysida ransomware families. The tooling, infrastructure, and shift in delivery mechanisms that Sophos analysts
Vendors
Products
Microsoft TeamsThe first phase, observed in March and April, relied on SEO-poisoned websites distributing trojanized Microsoft Teams MSI installers. These installers deployed a multi-stage PowerShell loader that communicated withWindows TerminalClickFix lure that instructs victims to open the Run dialog box, these lures direct users to open a Windows Terminal window. This ClickFix variation is known as ‘TerminalFix’.