The Lorem Ipsum shellcode loader and backdoor campaign has pivoted from Trojanized Microsoft Teams installers to ClickFix lures after Microsoft dismantled the Fox Tempest malware-signing-as-a-service infrastructure and revoked over 1,000 fraudulent signing certificates. Researchers at BlueVoyant now link the campaign to Rapid Brigantine (aka Vice Society), a financially motivated ransomware group active since mid-2022. The new delivery chain uses compromised WordPress sites injected with iframes displaying fake browser update prompts, tricking users into running a PowerShell command that silently installs the malware. The campaign's rapid adaptation highlights the resilience of modern threat actors and underscores the need for behavioral detection strategies rather than reliance on static indicators or assumptions about initial access vectors.

5m read timeFrom darkreading.com
Post cover image
Table of contents
Making a Quick Pivot to ClickFixClickFix Lures on WordPress SitesA Troubling Connection to Ransomware Actors
206 Impressions