Security1 publisher2 min readPublished
Sophos ties Windows Terminal ClickFix lures to a tunneling campaign running since March
Sophos linked ClickFix lures that open Windows Terminal, not the Run dialog, to STAC4924, a campaign it has tracked since at least March. The intrusions plant Lorem Ipsum Loader and a Python reverse-tunnel implant that relays attacker traffic through the victim host.
The Watch · Security desk

What happened
- In March and April the campaign spread trojanized Microsoft Teams MSI installers through SEO-poisoned websites, running a multi-stage PowerShell loader against victim-specific infrastructure.
- It abandoned signed installers for TerminalFix lures in late May, a switch that coincided with Microsoft taking down the signing service behind the operators' fraudulently obtained certificates.
- Lorem Ipsum Loader stores its shellcode as English words, decoded through a word-to-byte lookup table, to avoid the high entropy that flags packed payloads.
- Its command-and-control traffic moves as HTTP POST requests disguised as JPEG image uploads, with the real data encoded inside the picture.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure A ClickFix lure that opens Windows Terminal sits outside detections written to catch Run-dialog abuse, so hosts watched only for the classic lure stay reachable.
- decision With C2 resolving through Letsdiskuss and the payload pulled from python.org, reputation and domain filtering catch little, and detection has to sit on host behavior instead.
- precedent STAC4924 changed its whole delivery method within weeks of losing its certificate supplier, so a disclosure like this is likelier to force its next delivery swap than to end the campaign.
Following the lure runs a PowerShell command that downloads a ZIP holding a signed Windows binary, a malicious DLL and a batch script [6]. The script installs persistence and launches LockScreenContentServer.exe, which sideloads dui70.dll and runs Lorem Ipsum Loader [7]. Once running, the malware fires a series of PowerShell commands for reconnaissance and persistence [18], reads its live C2 list from an attacker profile on the legitimate Letsdiskuss platform [9], and writes a portable Python runtime into Users\Public\indigo, pulled straight from python.org [11]. That runtime executes client.py, an implant that opens an encrypted WebSocket to attacker servers and tags the host with a unique UUID [12]. Through the tunnel the operators relay traffic and reach internal network resources while the connection looks like ordinary web browsing [13].
Sophos opened these cases in August [1]. Several separate campaigns used Windows Terminal lures across 2026, so the technique is not one group's signature [3]. Sophos tied these particular intrusions to STAC4924 through the loader, the C2 infrastructure, the persistence and the DLL sideloading appearing together [5]. Lorem Ipsum Loader was first documented by BlueVoyant in February [4], and the tradecraft matches TerminalFix activity Microsoft reported in August [17].
The second phase, which added Active Directory reconnaissance and the Python tunnel, ran through September [16]. That is at least six months from the March start [1]. Sophos described the two phases as sharing many technical characteristics while using different delivery mechanisms [19].
What to watch
- Whether Sophos or another vendor attributes STAC4924 to a named group or state sponsor beyond the tracking cluster.
- Whether the operators pivot delivery again now that the Letsdiskuss dead drop and Python tunnel are public.
- Whether Microsoft's August TerminalFix reporting and Sophos's overlap point to one cluster or several using the same technique.