CyberSecurity SEE

TerminalFix Attacks Deploy Lorem Ipsum Loader to Establish Covert Tunnels into Corporate Networks

TerminalFix Attacks Deploy Lorem Ipsum Loader to Establish Covert Tunnels into Corporate Networks

New Findings on STAC4924: The Emergence of TerminalFix as a Covert Threat

A recently identified intrusion set, dubbed STAC4924, has been associated with sophisticated social-engineering strategies that deploy the Lorem Ipsum Loader, a malware specifically designed to establish covert reverse tunnels into enterprise networks. This troubling new trend highlights the evolving landscape of cybersecurity threats and underlines the need for organizations to be vigilant.

The STAC4924 activity marks a significant shift from the well-known ClickFix model, traditionally utilized within the Windows Run dialog. Now, this technique has migrated to the Windows Terminal, a relatively overlooked area, consequently increasing the risk for unsuspecting victims who may unwittingly execute complex PowerShell payloads without fully understanding the associated dangers. The transition to Windows Terminal not only leverages existing user familiarity with command-line interfaces but also hides malicious activities behind the façade of legitimate terminal commands.

In stark contrast to the more conventional ClickFix campaigns, which typically deliver basic commodity stealers, the STAC4924 operations have introduced a more intricate loader chain. This layered approach is notably designed for persistence, reconnaissance, command-and-control (C2) capabilities, and facilitating access to internal networks. The attack begins with a terminal command that downloads a ZIP archive. This archive contains a legitimate Windows binary named LockScreenContentServer.exe, in addition to a harmful dynamic-link library (DLL) file called dui70.dll and a batch script.

The batch script plays a crucial role in establishing persistence on the victim’s machine and launching the legitimate executable, which subsequently sideloads the nefarious DLL. Notably, this method manipulates the DLL search-order behavior, allowing the malware to run within the context of a trusted and signed Windows process, effectively masking its true nature from security tools that monitor for suspicious activities.

The sideloaded DLL houses the Lorem Ipsum Loader itself—a sophisticated shellcode-based implant that has been previously documented by cybersecurity experts at BlueVoyant, particularly in campaigns involving trojanized Microsoft Teams installers. A hallmark of this loader’s evasion techniques lies in its unique method of data storage; it encodes the shellcode as standard English words, thereby obscuring recognizable binary data. At runtime, a lookup table is employed to convert these innocent-seeming words back into hexadecimal bytes, complicating static inspections and hampering detection efforts based on entropy analysis.

BlueVoyant first traced this loader back to SEO-poisoned Teams installer campaigns that were active as early as February 2026. These malicious operations utilized installers that, while appearing valid and signed, were laced with harmful code and structured to camouflage their communications. The malware’s ability to contact attacker-controlled profiles on the legitimate Letsdiskuss platform allows it to act as dead-drop resolvers. Within these profiles, encoded data embedded in the content can be retrieved and decoded, guiding the loader to the active C2 infrastructure. This method permits operators to rotate their server backends without the need to rebuild the payload or to expose hardcoded domains to defenders.

Adding to the sophistication, the malware’s C2 traffic is engineered to mimic benign image transfers. It exchanges HTTP POST requests disguised as JPEG file transmissions, while the actual image data appendices contain the encoded command materials necessary for the attacker’s operations.

Sophos researchers disclosed insights on this ongoing threat in August 2026, highlighting cases involving deceptive prompts that urged users to open Windows Terminal and enter specific commands. The activity observed thus far aligns with earlier analyses by BlueVoyant, indicating that similar JFIF-based traffic patterns were detected, wherein data was cleverly concealed beyond expected image boundaries and protected via custom obfuscation methods.

The primary payload resulting from the STAC4924 operations delivers a portable Python environment set up under Users\Public\indigo, along with a custom client.py tunnel implant. This implant establishes an encrypted WebSocket session to the attacker’s infrastructure, allocating a unique UUID for each compromised system. This capability effectively transforms the infected machine into a covert proxy, enabling the operators to relay arbitrary TCP traffic through the victim’s device and reach internal systems without detection.

This functionality significantly escalates the intrusion’s severity. A reverse tunnel encrypted over TLS port 443 can seamlessly blend into conventional encrypted web traffic, granting unauthorized access to internal infrastructures visible from the compromised endpoint.

In a separate analysis of related TerminalFix activities, Microsoft documented various other techniques including Active Directory enumeration, domain-trust and domain-admin discovery, server probing, and scheduled-task persistence.

Sophos has expressed moderate confidence in linking both preceding and ongoing activities associated with STAC4924. The transition observed from early campaigns utilizing SEO-poisoned sites and trojanized Microsoft Teams installers to the current use of TerminalFix lures suggests a tactical adaptation rather than a complete overhaul of methods.

Organizations are urged to take proactive measures in investigating any unauthorized execution of LockScreenContentServer.exe, especially when loading dui70.dll. Security teams should also be vigilant for signs of PowerShell commands downloading ZIP files into public or ProgramData directories, along with unusual activity related to Letsdiskuss profiles and image uploads to non-image-specific endpoints.

As the threat landscape continues to adapt and evolve, Microsoft has made clear recommendations for organizations to treat potentially compromised endpoints as serious risks and prioritize credential rotation alongside lateral movement investigations within domain-joined systems.

Source link

Exit mobile version