2026-08-31HIGHThe fake-CAPTCHA lure now targets a console that can run multi-line scripts, not the one-line Run box
STAC4924
campaign · campaign:stac4924
Sophos X-Ops designation for a Lorem Ipsum Loader campaign active since at least March 2026: trojanized Microsoft Teams installers distributed through SEO-poisoned sites in March and April, then, from late May, TerminalFix ClickFix lures leading to DLL sideloading, a Python WebSocket tunnel and Active Directory reconnaissance. Sophos observed no encryption and says its observations support BlueVoyant's attribution to Rapid Brigantine (Sophos GOLD VICTOR, linked to Vice Society and Rhysida) (Sophos X-Ops, 2026-09-30).
Coverage
1
first 2026-08-31 → last 2026-10-05
Latest activity
2026-10-05
The fake-CAPTCHA lure now targets a console that can run multi-line scripts, not the one-line Run box
Peak priority
high
1 high
Targets
·
no sector or region stated
Sources cited
5
5 hosts
Defender insights
What each entry about STAC4924 tells a defender to do, newest first.
Triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
attributed to
- RhysidaBlueVoyant attributes Lorem Ipsum Loader to Rapid Brigantine (Sophos GOLD VICTOR, also Vice Society); Sophos says its STAC4924 observations support that attribution and that it saw no encryption
uses
- LoremIpsumLoaderSophos: the STAC4924 intrusions deploy Lorem Ipsum Loader (Sophos X-Ops, 2026-09-30)
overlaps with
- TerminalFixSophos: the tooling and tradecraft of STAC4924's second phase closely align with the TerminalFix activity Microsoft reported in August; Sophos says TerminalFix lures are not tied to one campaign
Story timeline
Hunting pivots
ATT&CK techniques (23 across 8 tactics)
23 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Resource DevelopmentObtain Capabilities: Code Signing Certificates · Stage Capabilities: SEO Poisoning
- Initial AccessDrive-by Compromise
- ExecutionScheduled Task/Job: Scheduled Task · Command and Scripting Interpreter: PowerShell · User Execution: Malicious File · User Execution: Malicious Copy and Paste · Hijack Execution Flow: DLL
- PersistenceScheduled Task/Job: Scheduled Task · Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- Privilege EscalationScheduled Task/Job: Scheduled Task · Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- StealthObfuscated Files or Information: Steganography · Obfuscated Files or Information: Encrypted/Encoded File · Masquerading: Match Legitimate Resource Name or Location · Hide Artifacts: Hidden Files and Directories · Hijack Execution Flow: DLL
- DiscoveryRemote System Discovery · Permission Groups Discovery: Domain Groups · System Information Discovery · Account Discovery: Domain Account · Domain Trust Discovery
- Command and ControlData Obfuscation: Steganography · Application Layer Protocol: Web Protocols · Web Service: Dead Drop Resolver · Ingress Tool Transfer · Protocol Tunneling
Resource Development TA0042
T1588.003Obtain Capabilities: Code Signing Certificates×1
Adversaries may buy and/or steal code signing certificates that can be used during targeting. Code signing is the process of digitally signing executables and scripts to confirm the software author and guarantee that the code has not been altered or corrupted. Code signing provides a level of authenticity for a program from the developer and a guarantee that the program has not been tampered with. Users and/or security tools may trust a signed piece of code more than an unsigned piece of code even if they don't know who issued the certificate or who the author is.
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
T1608.006Stage Capabilities: SEO Poisoning×1
Adversaries may poison mechanisms that influence search engine optimization (SEO) to further lure staged capabilities towards potential victims. Search engines typically display results to users based on purchased ads as well as the site’s ranking/score/reputation calculated by their web crawlers and algorithms.
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
Initial Access TA0001
T1189Drive-by Compromise×1
Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including:
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
Execution TA0002
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
T1059.001Command and Scripting Interpreter: PowerShell×1
Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
T1204.002User Execution: Malicious File×1
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
T1204.004User Execution: Malicious Copy and Paste×1
An adversary may rely upon a user copying and pasting code in order to gain execution. Users may be subjected to social engineering to get them to copy and paste code directly into a Command and Scripting Interpreter. One such strategy is "ClickFix," in which adversaries present users with seemingly helpful solutions (such as prompts to fix errors or complete CAPTCHAs) that instead instruct the user to copy and paste malicious code.
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
Persistence TA0003
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
Privilege Escalation TA0004
T1053.005Scheduled Task/Job: Scheduled Task×1
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel. In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and Windows Management Instrumentation (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
T1547.001Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder×1
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. These programs will be executed under the context of the user and will have the account's associated permissions level.
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
Stealth TA0005
T1027.003Obfuscated Files or Information: Steganography×1
Adversaries may use steganography techniques in order to prevent the detection of hidden information. Steganographic techniques can be used to hide data in digital media such as images, audio tracks, video clips, or text files.
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
T1027.013Obfuscated Files or Information: Encrypted/Encoded File×1
Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection. Encrypting and/or encoding file content aims to conceal malicious artifacts within a file used in an intrusion. Many other techniques, such as Software Packing, Steganography, and Embedded Payloads, share this same broad objective. Encrypting and/or encoding files could lead to a lapse in detection of static signatures, only for this malicious content to be revealed (i.e., Deobfuscate/Decode Files or Information) at the time of execution/use.
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
T1036.005Masquerading: Match Legitimate Resource Name or Location×1
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
T1564.001Hide Artifacts: Hidden Files and Directories×1
Adversaries may set files and directories to be hidden to evade detection mechanisms. To prevent normal users from accidentally changing special files on a system, most operating systems have the concept of a ‘hidden’ file. These files don’t show up when a user browses the file system with a GUI or when using normal commands on the command line. Users must explicitly ask to show the hidden files either via a series of Graphical User Interface (GUI) prompts or with command line switches (<code>dir /a</code> for Windows and <code>ls –a</code> for Linux and macOS).
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
T1574.001Hijack Execution Flow: DLL×1
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
Discovery TA0007
T1018Remote System Discovery×1
Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. Functionality could exist within remote access tools to enable this, but utilities available on the operating system could also be used such as Ping, <code>net view</code> using Net, or, on ESXi servers, `esxcli network diag ping`.
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
T1069.002Permission Groups Discovery: Domain Groups×1
Adversaries may attempt to find domain-level groups and permission settings. The knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as domain administrators.
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
T1082System Information Discovery×1
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes.
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
T1087.002Account Discovery: Domain Account×1
Adversaries may attempt to get a listing of domain accounts. This information can help adversaries determine which domain accounts exist to aid in follow-on behavior such as targeting specific accounts which possess particular privileges.
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
T1482Domain Trust Discovery×1
Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments. Domain trusts provide a mechanism for a domain to allow access to resources based on the authentication procedures of another domain. Domain trusts allow the users of the trusted domain to access resources in the trusting domain. The information discovered may help the adversary conduct SID-History Injection, Pass the Ticket, and Kerberoasting. Domain trusts can be enumerated using the `DSEnumerateDomainTrusts()` Win32 API call, .NET methods, and LDAP. The Windows utility Nltest is known to be used by adversaries to enumerate domain trusts.
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
Command and Control TA0011
T1001.002Data Obfuscation: Steganography×1
Adversaries may use steganographic techniques to hide command and control traffic to make detection efforts more difficult. Steganographic techniques can be used to hide data in digital messages that are transferred between systems. This hidden information can be used for command and control of compromised systems. In some cases, the passing of files embedded using steganography, such as image or document files, can be used for command and control.
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
T1071.001Application Layer Protocol: Web Protocols×1
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
T1102.001Web Service: Dead Drop Resolver×1
Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries may post content, known as a dead drop resolver, on Web services with embedded (and often obfuscated/encoded) domains or IP addresses. Once infected, victims will reach out to and be redirected by these resolvers.
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
T1105Ingress Tool Transfer×1
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
T1572Protocol Tunneling×1
Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems. Tunneling involves explicitly encapsulating a protocol within another. This behavior may conceal malicious traffic by blending in with existing traffic and/or provide an outer layer of encryption (similar to a VPN). Tunneling could also enable routing of network packets that would otherwise not reach their intended destination, such as SMB, RDP, or other traffic that would be filtered by network appliances or not routed over the Internet.
Evidence: 2026-08-31/microsoft-terminalfix-clickfix-reverse-tunnel-campaign · ATT&CK page ↗
Entries about STAC4924 (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- bsi.bund.de1 (20%)
- heise.de1 (20%)
- microsoft.com1 (20%)
- social.bund.de1 (20%)
- sophos.com1 (20%)
All cited sources (5)
- bsi.bund.deBSI (Bundesamt für Sicherheit in der Informationstechnik), BITS-2026-287419-1032, v1.0https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2026/2026-287419-1032.pdf?__blob=publicationFile
- heise.deheise online (Nico Ernst)https://www.heise.de/news/BSI-erklaert-ersten-Angriffsvektor-auf-Berliner-Behoerden-11444072.html
- microsoft.comMicrosoft Threat Intelligencehttps://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/
- social.bund.deBSI (Mastodon)https://social.bund.de/@bsi/117212729947889443
- sophos.comSophos X-Opshttps://www.sophos.com/en-us/blog/terminalfix-and-lorem-ipsum-loader-enable-covert-tunneling