TerminalFix: a ClickFix variant that pastes into Terminal or PowerShell instead of Windows' Run dialog, then chains DLL sideloading, steganographic payload delivery and a custom reverse-tunnel implant
First published 2026-08-31 · open finding →
Sophos X-Ops reports a campaign it tracks as STAC4924, active since at least March and closely aligned with this chain, with 19 pairings of a legitimate executable and a malicious DLL rather than one, a loader that stores shellcode as English words, C2 addresses read from a profile on a legitimate community platform, and a first phase of trojanized Teams installers before the TerminalFix lures. Sophos says its observations support BlueVoyant's attribution to the group linked to Vice Society and Rhysida, and that it has seen no encryption.
Sophos X-Ops reports a campaign it tracks as STAC4924, active since at least March, in two phases, whose tooling and tradecraft closely align with this chain (Sophos X-Ops, 2026-09-30). The first, in March and April, used SEO-poisoned websites distributing trojanized Microsoft Teams installer packages; from late May the campaign moved to TerminalFix lures, a shift Sophos says coincided with Microsoft's takedown of the malware-signing service that supplied the fraudulently obtained certificates (Sophos X-Ops, 2026-09-30). Sophos assesses with moderate confidence that the two phases are linked to the same group or closely associated actors, on the shared per-victim identifier callback and the use of a legitimate community platform as a dead-drop resolver for C2 addresses, and adds that the TerminalFix lure itself is not linked to a specific threat group or a single campaign, since several 2026 campaigns have used it (Sophos X-Ops, 2026-09-30).
Sophos lists 19 pairings of a legitimate executable and a malicious DLL observed between March and September, not only the lock-screen binary with dui70.dll: they include changepk.exe, werfaultsecure.exe, wuauclt.exe and embeddedapplauncher.exe, and helper executables named after Microsoft Edge and Teams (Sophos X-Ops, 2026-09-30). The loader stores shellcode bytes as English words with a separate lookup table to evade entropy-based detections, reads an attacker-controlled profile on the community platform to decode the current C2 server list, and then talks to C2 over HTTP POST requests that appear to carry JPEG images but hold encoded data (Sophos X-Ops, 2026-09-30).
BlueVoyant attributed the loader to the Rapid Brigantine group, which Sophos tracks as GOLD VICTOR (also known as Vanilla Tempest, DEV-0832, VICE SPIDER and Vice Society) and which has been linked to the Vice Society and Rhysida ransomware families; Sophos says its STAC4924 observations support that attribution but that it has not observed encryption in the campaign (Sophos X-Ops, 2026-09-30).