In August 2026, Sophos analysts began investigating a series of Managed Detection and Response (MDR) cases that involved ClickFix-style lures and resulted in the deployment of a Python-based tunneling implant. Instead of a typical ClickFix lure that instructs victims to open the Run dialog box, these lures direct users to open a Windows Terminal window. This ClickFix variation is known as 'TerminalFix'. Sophos tracks the campaign behind these cases as STAC4924. It also notes that the lure style is not unique to one group: TerminalFix is not linked to a specific threat group or a single campaign. In 2026, Sophos analysts have observed several malicious campaigns that incorporated these lures and resulted in multiple infection chains.
Why Terminal instead of the Run box?
The Run dialog is a single cramped line. Windows Terminal and PowerShell accept long, multi-line scripts. Microsoft's earlier TerminalFix research, published August 28, made the same point: sending victims to Terminal or PowerShell makes complex scripts more likely to run successfully. In the user's mind, "prove you're human" becomes "type this into a console". In practice it means "run my installer".
Section summary: TerminalFix is the same old ClickFix con with a bigger stage. The lure is familiar, but the payload it can deliver is far more elaborate.
The STAC4924 infection chain, step by step
Sophos describes the chain like this:
- The paste. By following the instructions in the TerminalFix lure, victims execute a PowerShell command that downloads a ZIP archive containing a legitimate Windows executable, a malicious DLL, and a batch script.
- Persistence and sideloading. The command then executes the batch script, which installs several persistence mechanisms and launches the legitimate LockScreenContentServer.exe binary. That binary then loads the malicious
dui70.dllsitting next to it. This abuse of DLL search-order behavior allows the malware to execute within the context of a trusted signed Windows process. - The loader. The DLL runs Lorem Ipsum Loader, a shellcode-based loader first observed by BlueVoyant in February 2026. The name fits. Its distinguishing evasion technique is the storage of shellcode as ordinary English words rather than recognizable binary data. A lookup table converts those words back into hexadecimal bytes at runtime, complicating static inspection and entropy-based detection.
- Dead-drop resolution. The loader contacts an attacker-controlled profile on the legitimate Letsdiskuss platform, extracts an encoded value from the profile, and uses it to obtain the current command-and-control server list. GBHackers points out that this approach lets operators rotate backend servers without rebuilding the payload or exposing hardcoded domains to defenders.
- Image-disguised C2. The malware's C2 traffic is designed to resemble benign image transfer. It exchanges HTTP POST requests that appear to carry JPEG files, while the appended image data actually contains encoded command material.
- The tunnel. The malware then executes a series of PowerShell commands to conduct reconnaissance, gather information, and establish persistence. It deploys a portable Python runtime to the Users\Public\indigo directory by downloading the legitimate Python embedded package from python.org and extracting it alongside malicious files. The runtime is then used to execute client.py, a custom tunneling implant that establishes an encrypted WebSocket connection to attacker-controlled servers and assigns a unique UUID to identify the compromised host.
The last step matters most. According to Sophos, the tunnel lets operators relay traffic through the infected PC to network resources it can reach, while blending in with ordinary encrypted web traffic. In effect, the attacker borrows the victim's PC as a doorway into the internal network.
Section summary: The chain is paste, sideload, word-encoded loader, resolver on a legitimate site, image-disguised C2, then a Python WebSocket tunnel. Every step is built to look like something harmless.
Two phases, one playbook
STAC4924 did not start with Terminal lures. Sophos linked the TerminalFix activity to an earlier STAC4924 phase observed in March and April. That phase relied on SEO-poisoned websites hosting trojanized Microsoft Teams MSI installers, which deployed multi-stage PowerShell loaders and used Letsdiskuss profiles as dead-drop resolvers.
Then the delivery method changed. Beginning in late May, the campaign transitioned from signed MSI installers to TerminalFix lures. The timing of this shift coincided with Microsoft's takedown of the malware-signing service that supplied the fraudulently obtained certificates used by the threat actors. The second phase has continued through September and leverages DLL sideloading, image-based steganography, Active Directory reconnaissance, and a Python reverse-tunnel implant.
Sophos's wording is "coincided", and that is the right word. The timing is suggestive: the actors lost their source of signed installers and switched to a technique that needs no signature at all, because the victim runs the code. Still, the report shows a timing match, not proof that the takedown caused the switch.
The link between the two phases is also an assessment, not a certainty. Sophos assesses with moderate confidence that both phases involve the same or closely associated operators, citing repeated UUID callback patterns, shared Letsdiskuss infrastructure, DLL sideloading tradecraft, and persistence masquerading as Microsoft or software-update components.
The bigger sideloading picture
Defenders who hunt only for LockScreenContentServer.exe plus dui70.dll will miss most of this campaign. Sophos published a table of host/DLL pairings it saw in STAC4924 between March and September. Pairings include:
| Legitimate host binary | Malicious DLL |
|---|---|
| lockscreencontentserver.exe | dui70.dll |
| phoneactivate.exe | dui70.dll |
| sessionmsg.exe | dui70.dll, duser.dll |
| wlrmdr.exe | dui70.dll |
| changepk.exe | slc.dll, faultrep.dll, sppcext.dll |
| werfaultsecure.exe | faultrep.dll |
| embeddedapplauncher.exe | sspicli.dll, secur32.dll |
| certenrollctrl.exe | certenroll.dll |
| vdsldr.exe | vdsutil.dll |
| wuauclt.exe | sspicli.dll |
The full list also includes binaries with update-themed names such as "Microsoft Edge Updates Helper.exe" paired with msvcp140.dll, plus a renamed WerFaultSecure.exe. Sophos says the full indicator set is in the SophosLabs GitHub repository, as the list is too long for the blog post.
Section summary: The way victims get infected changed from fake Teams installers to Terminal lures. What happens after infection stayed the same. And the attackers have used many host/DLL pairings, not just one.
How Microsoft's TerminalFix report compares
Microsoft's August 28 analysis covers a TerminalFix chain with clear overlap: fake Cloudflare Turnstile overlays on compromised websites, the same LockScreenContentServer.exe/dui70.dll sideload, Registry Run key and scheduled-task persistence, Active Directory reconnaissance, and a Python client.py reverse tunnel over WebSocket. Sophos itself says its observed tooling closely matches what Microsoft reported.
Some details differ, so don't merge the two reports:
- Image format: Microsoft describes payloads hidden in PNG pixel data. Sophos describes C2 POSTs that look like JPEGs.
- Specific indicators: Microsoft lists its tunnel destination as
gitnow[.]dev:443, the extraction path asC:\ProgramData\f47f2a8c21c9df4e, and the Python package as the embeddable 3.14.5 build launched windowless throughpythonw.exe. These belong to Microsoft's investigation. They are not confirmed STAC4924 indicators. - Observed outcomes: Microsoft says it did not observe follow-on attacker activity in the chain it analyzed. It treats privilege escalation, data theft and ransomware as risks that typically follow this kind of access, not as things it saw.
Microsoft's write-up also explains why the sideload works. LockScreenContentServer.exe statically imports dui70.dll, the Windows DirectUI engine. Windows checks the application's own folder before System32, so a planted copy wins.
Section summary: The two reports overlap heavily but are not identical. Know which report an indicator came from before you block on it.
Who is behind it?
BlueVoyant subsequently attributed Lorem Ipsum Loader to the Rapid Brigantine cybercriminal threat group, which Sophos Counter Threat Unit (CTU) researchers track as GOLD VICTOR (also known as Vanilla Tempest, DEV-0832, VICE SPIDER, and Vice Society). The group has been linked to the Vice Society and Rhysida ransomware families, and Sophos says STAC4924's tooling and infrastructure support BlueVoyant's attribution.
Sophos is also clear that it has not seen encryption in STAC4924. So this is not a ransomware outbreak. It is access being set up by a group with a ransomware history, which arguably makes catching it early more important.
What Windows admins should do now
Based on guidance from Sophos and Microsoft:
- Hunt by context, not filename. Microsoft advises alerting on
LockScreenContentServer.exerunning from anywhere other thanC:\Windows\SystemApps. Apply the same logic to the other host binaries in Sophos's table: a system binary sitting next to a DLL in ProgramData or a user folder is suspicious. - Look for Python where it doesn't belong. An embeddable Python runtime in
Users\Public(Sophos sawindigo), especially one launched throughpythonw.exewith no window, deserves a close look. - Correlate network signals. On their own, requests to Letsdiskuss, POSTs that look like images, and long-lived outbound WebSocket connections are each harmless. Seen together on the same host, they are a strong signal.
- Turn on PowerShell script-block logging. Microsoft also recommends Constrained Language Mode where practical, and AppLocker or App Control to limit PowerShell for standard users.
- Use Windows Terminal's paste warning. Microsoft suggests configuring Terminal to warn users when pasted text contains multiple lines. It's a small speed bump aimed squarely at this attack.
- Assume pivot access if you find a hit. Microsoft advises treating affected devices as network pivot points, checking for lateral movement, and rotating credentials reachable from the host, including domain admin credentials if the host was domain-joined.
- Retrain users. The simplest rule: no real CAPTCHA will ever ask you to paste a command into Terminal.
The takeaway
STAC4924 shows what a well-resourced crew does when one method stops working: it switches delivery and keeps everything after the initial infection the same. The defensive lesson is equally simple. Don't rely only on file signatures and blocklists for each new lure. Watch for the behaviors these campaigns depend on: trusted binaries loading neighbouring DLLs, PowerShell that users pasted in, out-of-place Python runtimes, and unusual tunnels leaving the network.
References
- TerminalFix Campaign Uses PowerShell and DLL Sideloading to Establish Covert C2 Tunnels cyberpress.org · 2026-10-01T11:07:35+00:00
- TerminalFix Attacks Deploy Lorem Ipsum Loader to Create Covert Tunnels Into Corporate Networks gbhackers.com
- TerminalFix and Lorem Ipsum Loader enable covert tunneling | SOPHOS sophos.com