Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Lorem Ipsum Loader is designed to retrieve the next-stage Lorem Ipsum Backdoor from C2 infrastructure obtained from attacker-controlled profiles hosted on social networking platforms. | If the user complies, the ClickFix lure initiates a multi-stage infection chain that ultimately deploys the Lorem Ipsum Loader, a malware family BlueVoyant first documented in May 2026.
The Lorem Ipsum Loader is designed to retrieve the next-stage Lorem Ipsum Backdoor from C2 infrastructure obtained from attacker-controlled profiles hosted on social networking platforms. | If the user complies, the ClickFix lure initiates a multi-stage infection chain that ultimately deploys the Lorem Ipsum Loader, a malware family BlueVoyant first documented in May 2026.
The Click Fix technique has also been observed in an active campaign that uses at least five compromised WordPress sites as a starting point to deliver a nascent loader, and backdoor codenamed Lorem Ipsum Loader.
The Click Fix technique has also been observed in an active campaign that uses at least five compromised WordPress sites as a starting point to deliver a nascent loader, and backdoor codenamed Lorem Ipsum Loader.
34 distinct techniques documented for this family, organized by ATT&CK tactic.
Campaign infrastructure is consistently registered through NameCheap with Withheld-for-Privacy domain privacy service out of Iceland and weaponized within hours to days of registration
In October 2025, MSTIC publicly attributed and disrupted a Rapid Brigantine campaign distributing fake MSTeamsSetup.exe files hosted on Teams-themed malicious domains ... driven by SEO poisoning and malvertising.
For the new ClickFix delivery model, Lorem Ipsum's operator is currently using at least five legitimate but compromised WordPress websites to host its ClickFix lures.
The pivot to ClickFix lures hosted on compromised WordPress (WP) sites significantly broadens the potential victim pool.
In the March 2026 iteration of the campaign, the operators relied on plainraw[.]com ... to serve gzip-compressed, hex-encoded PowerShell payloads under disposable /raw/<hex> URL paths embedded in the trojanized MSI installers.
MITRE ATT&CK Techniques ... T1608.001 (Stage Capabilities: Upload Malware)
The PowerShell script decrypts a hardcoded Base64-encoded payload embedded within itself using AES encryption.
...downloads a ZIP file and an outdated version of Node.js released in 2017 (version 7.10.1) to execute JavaScript-based payloads present within the archive...
The MSI file contains a custom action that executes the PowerShell loader component silently by incorporating the -WindowStyle Hidden flag
The pivot to ClickFix in late May 2026 eliminates the code-signing requirement entirely, substituting the legitimacy of a validly signed installer with a different form of legitimacy: a user voluntarily executing the malicious command in their own terminal.
the pop-op instructs the user to paste a provided PowerShell command, disguised as a Microsoft Edge security intelligence update, into their Windows Terminal.
The website displays an iframe, presenting the user with a fake pop up indicating that their browser is out of date. The iframe includes instructions on how to remediate, simply by opening up windows terminal ( wt.exe ) and pasting a command into the terminal.
the Lorem Ipsum loader begins by resolving various Windows libraries using the API LoadLibraryA ... then resolves specific corresponding APIs using GetProcAddress
The Lorem Ipsum campaign initially relied on SEO poisoning to lure users into downloading Trojanized Microsoft Teams installers signed with valid Microsoft Trusted Signing certificates.
The MSI file contains a custom action that executes the PowerShell loader component silently by incorporating the -WindowStyle Hidden flag
newer versions employ a more sophisticated approach, rebuilding the payload through a substitution cipher-based decoding algorithm.
Following API resolution, the shellcode creates a mutex via CreateMutexA to prevent concurrent execution.
the platform itself is entirely legitimate and has not been compromised; it is being abused in much the same way that threat actors have historically abused Pastebin, GitHub Gists, Telegram channels, and Google Docs
the loader abuses letsdiskuss[.]com, a legitimate India-based question-and-answer/blogging platform, as a dead-drop resolver for C2 infrastructure across at least four attacker-controlled profiles.
Each infection beacons to three redundant Cloudflare-fronted C2 domains using the same per-victim UUID, complicating takedown and rendering IP-based blocking ineffective.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A JavaScript-delivered loader/backdoor distributed through compromised WordPress sites and ClickFix lures. It uses an outdated Node.js runtime, establishes persistence through DLL side-loading, decodes an embedded payload, and retrieves the next-stage Lorem Ipsum Backdoor from attacker-controlled social-network profiles and C2 infrastructure.
A multistage shellcode loader and backdoor delivered first via Trojanized Microsoft Teams installers and later via ClickFix lures on compromised WordPress sites. It uses DLL sideloading, encrypted payloads, and a dead-drop C2 mechanism via LetsDiskuss[.]com to retrieve command-and-control server addresses, and assigns unique identifiers to track victim infections.
A follow-on backdoor retrieved by Lorem Ipsum Loader from attacker-controlled dead-drop/C2 infrastructure.
A multi-stage malware family delivered via trojanized Microsoft Teams installers in an SEO-poisoning campaign. It uses PowerShell and later DLL sideloading to decode and launch shellcode, establishes persistence via Run keys, resolves C2 through attacker-controlled letsdiskuss.com profiles acting as dead-drop resolvers, and communicates through JFIF-disguised image traffic with appended encrypted data. The backdoor collects host information, encrypts it, and supports execution of additional payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.