TerminalFix and Lorem Ipsum Loader Enable Covert Tunneling
Sophos, Wednesday, September 30th, 2026
Sophos details STAC4924, a campaign using TerminalFix lures and Lorem Ipsum Loader to deploy a Python tunneling implant.
Sophos MDR analysts investigated cases where ClickFix-style lures told victims to open Windows Terminal, a variant called TerminalFix, leading to a Python-based tunneling implant.
The PowerShell command downloads a ZIP containing a legitimate executable that sideloads a malicious DLL running Lorem Ipsum Loader, which stores shellcode as English words to evade entropy-based detection and retrieves data from an attacker profile on the Letsdiskuss platform.
Sophos tracks the broader campaign, active since at least March, as STAC4924.