GBHackers

TerminalFix Attacks Deploy Lorem Ipsum Loader to Create Covert Tunnels Into Corporate Networks


A newly tracked intrusion set, STAC4924, is using TerminalFix social-engineering lures to deploy the Lorem Ipsum Loader and establish covert reverse tunnels into enterprise environments.

The activity shifts the familiar ClickFix model from the Windows Run dialog to Windows Terminal, increasing the likelihood that victims execute complex PowerShell payloads without recognizing the risk.

Unlike conventional ClickFix campaigns, which often deliver commodity stealers, this operation deploys a layered loader chain built for persistence, reconnaissance, command-and-control, and internal network access.

The terminal command downloads a ZIP archive containing a legitimate Windows binary, LockScreenContentServer.exe, a malicious dui70.dll, and a batch script.

The script establishes persistence and launches the legitimate executable, which sideloads the attacker-controlled DLL.

This abuse of DLL search-order behavior allows the malware to execute within the context of a trusted signed Windows process.

The sideloaded DLL contains Lorem Ipsum Loader, a shellcode-based implant previously documented by BlueVoyant in campaigns involving trojanized Microsoft Teams installers.

Its distinguishing evasion technique is the storage of shellcode as ordinary English words rather than recognizable binary data.

A lookup table converts those words back into hexadecimal bytes at runtime, complicating static inspection and entropy-based detection.

BlueVoyant previously linked the loader to SEO-poisoned Teams installer campaigns active from at least February 2026, where the malware used malicious yet validly signed installers, dead-drop infrastructure, and image-disguised C2 traffic.

After execution, Lorem Ipsum Loader contacts attacker-controlled profiles on the legitimate Letsdiskuss platform.

The profiles act as dead-drop resolvers: encoded data embedded in profile content is retrieved, decoded, and used to identify the active C2 infrastructure.

This approach lets operators rotate backend servers without rebuilding the payload or exposing hardcoded domains to defenders.

The malware’s C2 traffic is designed to resemble benign image transfer. It exchanges HTTP POST requests that appear to carry JPEG files, while the appended image data actually contains encoded command material.

Sophos Researchers said that, the Managed Detection and Response cases in August 2026 after identifying fake verification prompts that instructed users to open Windows Terminal and paste a command.

TerminalFix Attacks

Similar JFIF-based traffic was previously observed in BlueVoyant’s analysis of Lorem Ipsum, where data was concealed beyond expected image boundaries and protected with custom obfuscation routines.

TerminalFix lures (Source : Sophos).

The final payload is a portable Python environment installed under UsersPublicindigo, alongside a custom client.py tunnel implant.

The implant establishes an encrypted WebSocket session to attacker infrastructure and assigns each compromised system a unique UUID.

From there, operators can relay arbitrary TCP traffic through the victim host, effectively converting it into a covert proxy for reaching internal systems.

This capability materially raises the severity of the intrusion. A reverse tunnel over TLS port 443 can blend with ordinary encrypted web traffic while enabling access to systems visible from the compromised endpoint.

Microsoft’s separate TerminalFix analysis found that related activity included Active Directory enumeration, domain-trust discovery, domain-admin discovery, server probing, scheduled-task persistence, and SOCKS-style TCP proxying through a WebSocket tunnel.

Sophos assesses with moderate confidence that STAC4924’s earlier and later activity phases are connected. The first phase, seen in March and April, used SEO-poisoned sites and trojanized Microsoft Teams MSI installers.

The campaign then pivoted in late May to TerminalFix lures, a change that coincided with Microsoft’s disruption of Fox Tempest, a malware-signing-as-a-service operation that had issued more than 1,000 fraudulent short-lived certificates to cybercriminal customers.

The shift suggests an adaptation in initial-access tradecraft rather than a wholesale redesign.

Both phases used Letsdiskuss dead-drop resolvers, per-victim UUID tracking, DLL sideloading, deceptive persistence entries, and scheduled tasks.

The operators appear to have replaced signed installer delivery with user-assisted PowerShell execution while retaining the same post-compromise framework.

Organizations should investigate any execution of LockScreenContentServer.exe outside normal Windows locations, particularly where it loads dui70.dll.

Security teams should also hunt for PowerShell downloading ZIP files into public or ProgramData directories, unusual access to Letsdiskuss profiles, image uploads to non-image endpoints, hidden Python installations, and pythonw.exe executing client.py.

Microsoft specifically recommends treating infected endpoints as potential network pivot points and prioritizing credential rotation and lateral-movement investigation on domain-joined systems.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC



Source link