We use cookies. By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
TechGeer Black Text Logo Light Header TechGeer Main Logo
  • News
    • AI News
    • Cybersecurity News
    • Streaming News
    • Tech News
  • Statistics
    • Entertainment
    • Gadgets and Hardware
    • Internet Security
    • Lifestyle
    • Marketing and Finance
    • Science
    • Web and Software
    • Workplace and Business
  • Streaming
  • Security
    • VPN
    • Spy
    • Antivirus
    • Torrenting
  • AI
  • About Us
    • Why Trust Us
    • Editorial Policy
    • Our Writers and Editors
    • Terms of Use
    • How We Make Money
    • Get in Touch
Reading: Sophos Warns of TerminalFix Campaign Using Windows Terminal to Spread Malware
TechGeerTechGeer
Search
  • News
    • AI News
    • Cybersecurity News
    • Streaming News
    • Tech News
  • Statistics
    • Entertainment
    • Gadgets and Hardware
    • Internet Security
    • Lifestyle
    • Marketing and Finance
    • Science
    • Web and Software
    • Workplace and Business
  • Streaming
  • Security
    • VPN
    • Spy
    • Antivirus
    • Torrenting
  • AI
  • About Us
    • Why Trust Us
    • Editorial Policy
    • Our Writers and Editors
    • Terms of Use
    • How We Make Money
    • Get in Touch
Have an existing account? Sign In
Follow US
  • Terms of Use
  • Privacy Policy
© 2024 TechGeer.com. All Rights Reserved.
Home » News » Cybersecurity » Sophos Warns of TerminalFix Campaign Using Windows Terminal to Spread Malware

Sophos Warns of TerminalFix Campaign Using Windows Terminal to Spread Malware

Olivia Carter
Last updated: October 2, 2026 7:29 am
By Olivia Carter
7 Min Read
Share
We conduct in-depth independent evaluations before making a recommendation. If you buy through links on our site, we may earn a fee that supports our mission.
  • Sophos uncovered a TerminalFix campaign that tricks Windows users into running commands through Windows Terminal.
  • The attack deploys Lorem Ipsum Loader and creates an encrypted WebSocket tunnel for access through compromised networks.
  • Sophos links the tooling to an actor associated with Vice Society and Rhysida, but it has seen no ransomware encryption in this campaign.

A new cybercrime campaign has replaced a familiar ClickFix trick with a different method that targets Windows users. Sophos X-Ops says the attackers now convince victims to open Windows Terminal and run a command themselves.

The campaign deploys Lorem Ipsum Loader before creating an encrypted tunnel into compromised networks. Sophos tracks the wider activity as STAC4924 and says it has operated since at least March.

In This Article
TerminalFix Changes the ClickFix Attack MethodLorem Ipsum Loader Creates a Hidden TunnelAttackers Changed Tactics After May DisruptionSophos Links Tooling to a Known Ransomware Actor

TerminalFix Changes the ClickFix Attack Method

The new technique uses what Sophos calls TerminalFix. It follows the same basic idea as ClickFix but changes how attackers get victims to execute malicious commands.

Traditional ClickFix campaigns often direct users toward the Windows Run dialog. TerminalFix instead tells users to open Windows Terminal. The victim then follows instructions that trigger a PowerShell command. This command downloads a ZIP file which contains several files. The download contains a legitimate executable file from Windows, a malicious dynamic-link library file, and a batch script.

The batch script sets up persistence and starts the legitimate executable. The executable then loads the malicious DLL through DLL sideloading. This technique gives attackers a way to hide malicious activity behind legitimate Windows components. The malicious DLL launches Lorem Ipsum Loader, which continues the infection process.

Sophos first began examining these cases in August 2026. Researchers later connected the activity to a larger campaign that had already operated for several months. The company also stresses that TerminalFix does not belong to one specific threat group. Several campaigns have used similar lures during the year.

Lorem Ipsum Loader Creates a Hidden Tunnel

Lorem Ipsum Loader forms a major part of the attack chain. BlueVoyant first reported the shellcode-based loader in February this year. The malware uses an unusual method to store its shellcode. Instead of keeping the data as obvious binary bytes, it represents the values with English words.

A lookup table then helps the malware rebuild the original byte values. Sophos says this approach helps the loader avoid some detection methods that examine file entropy.

After execution, the loader contacts an attacker-controlled profile on the legitimate Letsdiskuss platform. It retrieves encoded information from that profile to find its current command-and-control infrastructure. The malware then sends traffic that looks like JPEG image data. However, the apparent image traffic carries encoded information for communication with the attackers.

The campaign later installs a portable Python runtime. It uses that environment to launch a custom client.py tunneling implant. The implant creates an encrypted WebSocket connection with attacker-controlled servers. It also gives each compromised machine a unique identifier.

That tunnel creates a more serious network risk. Attackers can use the compromised computer as a relay point for reaching resources inside the network of the victim. The technique can also help the attackers blend their traffic with normal web activity. This makes the compromise harder to spot through basic network monitoring.

Attackers Changed Tactics After May Disruption

Sophos found evidence that STAC4924 has gone through at least two major phases. The earlier phase appeared during March and April. At that stage, attackers used SEO-poisoned websites to distribute modified Microsoft Teams MSI installers. Those installers launched a multi-stage PowerShell infection process.

The campaign later changed direction. In late May, attackers moved away from signed MSI installers and adopted TerminalFix lures. The timing matched the disruption of Microsoft of a malware-signing service. That service had supplied fraudulent certificates that helped attackers make malicious software appear more trustworthy.

The new phase continued through September. It added DLL sideloading, image-based steganography, Active Directory reconnaissance, and the Python-based reverse tunnel. Sophos found several similarities between the two phases. Both used attacker-controlled profiles as dead-drop resolvers. Both also used DLL sideloading and persistence methods that could make malicious components appear connected to legitimate software.

For that reason, Sophos assesses with moderate confidence that the two phases involve the same group or closely connected actors. The company describes the change as an evolution in delivery methods rather than a complete change in the wider playbook of the attackers.

Sophos Links Tooling to a Known Ransomware Actor

Sophos also examined the people or groups that may sit behind the activity. Its researchers say the tooling and infrastructure support an earlier attribution made by BlueVoyant. Further, BlueVoyant linked Lorem Ipsum Loader to Rapid Brigantine. Sophos tracks that threat actor as GOLD VICTOR.

The actor also carries several other names, including Vanilla Tempest, DEV-0832, and VICE SPIDER. Researchers have historically linked the group to Vice Society and Rhysida ransomware operations.

Another ransomware group has also drawn attention for its growing global activity, with The Gentlemen emerging as a highly active cybercrime syndicate. However, that connection needs an important qualification. Sophos has not seen ransomware encryption during the current STAC4924 activity.

The researchers therefore do not claim that the latest TerminalFix infections led to Rhysida ransomware attacks. The ransomware connection comes from the historical activity of the group and the attribution of the associated tooling. The current campaign instead focuses on gaining access and creating a covert route through compromised systems.

Sophos recommends that organizations watch for signs of TerminalFix activity and train employees to recognize ClickFix-style lures. The company also provides detection guidance and indicators for defenders investigating possible infections.

Share This Article
Facebook LinkedIn Reddit Copy Link
ByOlivia Carter
Olivia Carter is a technology journalist and privacy analyst who covers cybersecurity, consumer technology, artificial intelligence, and digital privacy. She has extensive experience reporting on breaking cyber incidents, software vulnerabilities, and regulatory developments. Her goal is to make technical topics accessible while delivering accurate, research-driven reporting for everyday readers and IT professionals.
Leave a Comment Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related Articles

Paymium Confirms Customer Data Exposed in Brevo Security Breach
Cybersecurity

French Crypto Platform Paymium Confirms Customer Data Exposed in Brevo Security Breach

September 24, 2026
Palo Alto Networks Warns of Critical PAN-OS Flaw Allowing Remote Code Execution
Cybersecurity

Palo Alto Networks Warns of High-Severity PAN-OS Flaw Enabling Unauthenticated Root RCE

September 15, 2026
Paris Man Accused of Hacking Police and Courts in €1 Million Scam
Cybersecurity

Paris Man Accused of Hacking Police and Courts in €1 Million Scam

September 15, 2026
Microsoft Fixes Windows BitLocker Vulnerability that could Enable Code Execution
Cybersecurity

Microsoft Fixes Windows BitLocker Vulnerability That Could Enable Code Execution

September 10, 2026
TechGeer Black Text Logo Light Header TechGeer Main Logo

Discover the latest in tech at TechGeer.com: AI, software, VPNs, privacy, monitoring, gaming, streaming, and alternatives. Your go-to source for cutting-edge news and guides in the digital world.

Navigation

  • News
  • Statistics
  • Security and Privacy Guides
  • Monitoring
  • VPN
  • Torrenting
  • Streaming & Geoblocking
  • Software and Apps
  • Artificial Intelligence

Company

  • About Us
  • Why Trust Us
  • Editorial Policy
  • Disclaimer
  • How We Evaluate
  • Career
  • Contact

Follow Us

TechGeer Ltd
Office 1214 727 51
High Streat, East
London E72JA
United Kingdom

© 2024 TechGeer.com. All Rights Reserved.
  • Terms of Use
  • Privacy Policy
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?

Not a member? Sign Up