A campaign that has been planting backdoors on Windows PCs since at least March has changed how it gets in: instead of fake Microsoft Teams installers, victims are now talked into pasting a command into Windows Terminal themselves. The original report from Sophos X-Ops Threat Research tracks the activity as STAC4924 and supports an attribution to a group linked to the Vice Society and Rhysida ransomware operations.
The lure is a twist on ClickFix, the fake "fix this error" prompt that tricks people into running attacker code. The usual version tells victims to open the Windows Run box; this one, which Sophos calls TerminalFix, sends them to a Terminal window instead. Sophos began investigating the cases through its managed detection and response service in August 2026 and says TerminalFix is not tied to any single group, having appeared in several campaigns this year. IntelFusions has covered a string of ClickFix variants in recent weeks.
Shellcode spelled out in English words
The pasted PowerShell command downloads a ZIP holding a legitimate Windows program, a malicious DLL and a batch script. The script sets up persistence and launches LockScreenContentServer.exe, which sideloads the rogue dui70.dll. That DLL carries Lorem Ipsum Loader, first observed by BlueVoyant in February 2026, which stores its shellcode as ordinary English words plus a lookup table, a way to slip past detections that look for random-looking data.
The loader then reads an attacker-controlled profile on the legitimate Letsdiskuss platform to learn its current command servers, and talks to them with HTTP POST requests dressed up as JPEG images that actually carry encoded data. After reconnaissance, it drops the official embedded Python package from python.org into Users\Public\indigo and runs client.py, a custom implant that opens an encrypted WebSocket tunnel and tags each victim with a unique ID. That tunnel lets the operators relay traffic through the infected PC to reach internal resources while blending in with normal web traffic.
Two phases, one playbook
The first phase, in March and April, used SEO-poisoned websites pushing trojanized Teams MSI installers and already leaned on letsdiskuss[.]com profiles as dead drops. The switch to TerminalFix came in late May, around the time Microsoft took down the malware-signing service that had supplied the group's fraudulently obtained certificates. The per-victim ID scheme, the dead-drop site and DLL sideloading carry across both phases, and Sophos lists 19 sideloading pairs used between March and September, many of them abusing Windows binaries such as changepk.exe, wlrmdr.exe and werfaultsecure.exe. Sophos also says the tooling closely matches TerminalFix activity Microsoft reported in August.
BlueVoyant attributed Lorem Ipsum Loader to the group it calls Rapid Brigantine, which Sophos tracks as GOLD VICTOR and which is also known as Vanilla Tempest and Vice Society. Sophos assesses with moderate confidence that both phases come from the same or closely associated actors and says its findings support BlueVoyant's attribution. It has not seen any files encrypted in this campaign.
Teach staff that no site needs a Terminal command
Sophos detects the tooling as Troj/Loader-RV, Troj/Loader-RW, Troj/Loader-RT and ATK/PyTune-B, among other behavioral rules, and has published the full indicator list in the SophosLabs GitHub repository because of its size. The artifacts it describes give defenders clear places to look: Windows system binaries running from odd folders beside DLLs such as dui70.dll, a portable Python runtime under Users\Public\indigo, and traffic to letsdiskuss[.]com. Sophos also urges training so employees recognize ClickFix-style lures, which it says keep increasing and evolving.
No encryption yet is not the same as no threat. A group with this lineage holding a live tunnel into a network is reason enough to go hunting now.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.