Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issues › Volume 342, Issue 5 › IT Vendor News › Sophos

TerminalFix and Lorem Ipsum Loader Enable Covert Tunneling

Sophos, Wednesday, September 30th, 2026

Sophos details STAC4924, a campaign using TerminalFix lures and Lorem Ipsum Loader to deploy a Python tunneling implant.

Sophos MDR analysts investigated cases where ClickFix-style lures told victims to open Windows Terminal, a variant called TerminalFix, leading to a Python-based tunneling implant.

The PowerShell command downloads a ZIP containing a legitimate executable that sideloads a malicious DLL running Lorem Ipsum Loader, which stores shellcode as English words to evade entropy-based detection and retrieves data from an attacker profile on the Letsdiskuss platform.

Sophos tracks the broader campaign, active since at least March, as STAC4924.

more →  ·  More from Sophos →