Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Sophos analysts identified the deployment of Lorem Ipsum Loader, a shellcode-based loader first observed by BlueVoyant in February 2026.
Sophos analysts identified the deployment of Lorem Ipsum Loader, a shellcode-based loader first observed by BlueVoyant in February 2026.
Sophos analysts identified the deployment of Lorem Ipsum Loader, a shellcode-based loader first observed by BlueVoyant in February 2026.
The Click Fix technique has also been observed in an active campaign that uses at least five compromised WordPress sites as a starting point to deliver a nascent loader, and backdoor codenamed Lorem Ipsum Loader.
The Click Fix technique has also been observed in an active campaign that uses at least five compromised WordPress sites as a starting point to deliver a nascent loader, and backdoor codenamed Lorem Ipsum Loader.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
Campaign infrastructure is consistently registered through NameCheap with Withheld-for-Privacy domain privacy service out of Iceland and weaponized within hours to days of registration
In October 2025, MSTIC publicly attributed and disrupted a Rapid Brigantine campaign distributing fake MSTeamsSetup.exe files hosted on Teams-themed malicious domains ... driven by SEO poisoning and malvertising.
The pivot to ClickFix lures hosted on compromised WordPress (WP) sites significantly broadens the potential victim pool.
In the March 2026 iteration of the campaign, the operators relied on plainraw[.]com ... to serve gzip-compressed, hex-encoded PowerShell payloads under disposable /raw/<hex> URL paths embedded in the trojanized MSI installers.
MITRE ATT&CK Techniques ... T1608.001 (Stage Capabilities: Upload Malware)
Both phases establish persistence through auto-run entries masquerading as legitimate Microsoft or software-update components, often reinforced with scheduled tasks.
“[ClickFix] substitut[es] the legitimacy of a validly signed installer with... a user voluntarily executing the malicious command in their own terminal.”
Victims execute a PowerShell command that downloads a ZIP archive... The malware then executes a series of PowerShell commands to conduct reconnaissance, gather information, and establish persistence.
...downloads a ZIP file and an outdated version of Node.js released in 2017 (version 7.10.1) to execute JavaScript-based payloads present within the archive...
The MSI file contains a custom action that executes the PowerShell loader component silently by incorporating the -WindowStyle Hidden flag
TerminalFix lures direct users to open a Windows Terminal window, where victims execute a PowerShell command.
The website displays an iframe, presenting the user with a fake pop up indicating that their browser is out of date. The iframe includes instructions on how to remediate, simply by opening up windows terminal ( wt.exe ) and pasting a command into the terminal.
Both phases establish persistence through auto-run entries masquerading as legitimate Microsoft or software-update components, often reinforced with scheduled tasks.
Both phases establish persistence through auto-run entries masquerading as legitimate Microsoft or software-update components, often reinforced with scheduled tasks.
Lorem Ipsum Loader attempts to evade entropy-based detections by storing shellcode bytes as English words rather than raw binary data.
The image files contain encoded data that the malware extracts and decodes to facilitate C2 communications.
the Lorem Ipsum loader begins by resolving various Windows libraries using the API LoadLibraryA ... then resolves specific corresponding APIs using GetProcAddress
Auto-run entries masquerad[e] as legitimate Microsoft or software-update components.
The MSI file contains a custom action that executes the PowerShell loader component silently by incorporating the -WindowStyle Hidden flag
newer versions employ a more sophisticated approach, rebuilding the payload through a substitution cipher-based decoding algorithm.
Following API resolution, the shellcode creates a mutex via CreateMutexA to prevent concurrent execution.
The loader then communicates with the C2 servers using HTTP POST requests that appear to contain JPEG image files.
Lorem Ipsum Loader issues an HTTP request to an attacker-controlled profile hosted on the legitimate Letsdiskuss platform... to retrieve the current set of C2 servers.
C2 dead drops were stored in Digital Point user profiles; strings in profile information were decoded by the malware into command-and-control domains.
Each infection beacons to three redundant Cloudflare-fronted C2 domains using the same per-victim UUID, complicating takedown and rendering IP-based blocking ineffective.
102 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware loader identified in intrusions investigated in August 2026 involving TerminalFix social-engineering lures and deployment of a Python-based tunneling implant. The intrusions involved command-and-control infrastructure, persistence, and DLL sideloading and were linked to the STAC4924 campaign. The content does not detail the loader's specific functionality.
A shellcode-based loader that evades entropy-based detection by representing shellcode bytes as English words and decoding them through a lookup table. It uses Letsdiskuss profiles as dead-drop resolvers to obtain C2 servers, exchanges encoded data disguised as JPEG files over HTTP POST, and deploys a portable Python runtime to execute a custom encrypted WebSocket reverse-tunneling implant.
Shellcode-based loader deployed through DLL sideloading in the STAC4924 campaign. It stores shellcode bytes as English words with a lookup table to evade entropy-based detection. It retrieves encoded C2 addresses from an attacker-controlled Letsdiskuss profile and exchanges encoded data disguised as JPEG files over HTTP. The subsequent infection chain performs reconnaissance, establishes persistence, and deploys an unnamed Python tunneling implant that provides encrypted WebSocket access through compromised hosts.
Malware whose operators reportedly shifted in late May 2026 from signed MSI delivery via SEO/malvertising infrastructure to ClickFix social-engineering delivery, in which victims execute a malicious terminal command.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.