<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/lorem-ipsum-malware-pivots-to-clickfix-delivery-oe9802vrx" -->

---
title: &#x27;Lorem Ipsum&#x27; Malware Pivots to ClickFix Delivery
description: The Lorem Ipsum shellcode loader and backdoor campaign has pivoted from Trojanized Microsoft Teams installers to ClickFix lures after Microsoft dismantled the...
canonical: https://daily.dev/posts/lorem-ipsum-malware-pivots-to-clickfix-delivery-oe9802vrx
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: &#x27;Lorem Ipsum&#x27; Malware Pivots to ClickFix Delivery | daily.dev
og:description: The Lorem Ipsum shellcode loader and backdoor campaign has pivoted from Trojanized Microsoft Teams installers to ClickFix lures after Microsoft dismantled the...
og:url: https://daily.dev/posts/lorem-ipsum-malware-pivots-to-clickfix-delivery-oe9802vrx
og:image: https://api.daily.dev/og/posts/oE9802vrx.png
og:image:alt: &#x27;Lorem Ipsum&#x27; Malware Pivots to ClickFix Delivery
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# 'Lorem Ipsum' Malware Pivots to ClickFix Delivery

**[Dark Reading](https://daily.dev/sources/dr)** · 5 min read · 0 upvotes · 0 comments

## Summary

The Lorem Ipsum shellcode loader and backdoor campaign has pivoted from Trojanized Microsoft Teams installers to ClickFix lures after Microsoft dismantled the Fox Tempest malware-signing-as-a-service infrastructure and revoked over 1,000 fraudulent signing certificates. Researchers at BlueVoyant now link the campaign to Rapid Brigantine (aka Vice Society), a financially motivated ransomware group active since mid-2022. The new delivery chain uses compromised WordPress sites injected with iframes displaying fake browser update prompts, tricking users into running a PowerShell command that silently installs the malware. The campaign's rapid adaptation highlights the resilience of modern threat actors and underscores the need for behavioral detection strategies rather than reliance on static indicators or assumptions about initial access vectors.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.darkreading.com/cyberattacks-data-breaches/lorem-ipsum-malware-clickfix-delivery>

## Similar posts on daily.dev

- [ClickFix techniques evolve in new infostealer campaigns](https://daily.dev/posts/clickfix-techniques-evolve-in-new-infostealer-campaigns-mufrpsfhw) · CSO Online · 0 upvotes · 0 comments
- [And the Winner in Dominant Malware Delivery? ClickFix](https://daily.dev/posts/and-the-winner-in-dominant-malware-delivery-clickfix-bnaaccteu) · Dark Reading · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#wordpress](https://daily.dev/tags/wordpress), [#malware](https://daily.dev/tags/malware), [#ransomware](https://daily.dev/tags/ransomware)

[View this post on daily.dev](https://daily.dev/posts/lorem-ipsum-malware-pivots-to-clickfix-delivery-oe9802vrx)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"'Lorem Ipsum' Malware Pivots to ClickFix Delivery","url":"https://daily.dev/posts/lorem-ipsum-malware-pivots-to-clickfix-delivery-oe9802vrx","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/lorem-ipsum-malware-pivots-to-clickfix-delivery-oe9802vrx"},"datePublished":"2026-06-16T14:16:13.626Z","dateModified":"2026-06-16T14:16:36.339Z","description":"The Lorem Ipsum shellcode loader and backdoor campaign has pivoted from Trojanized Microsoft Teams installers to ClickFix lures after Microsoft dismantled the...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e6cd1c5be409b1e4bc8b8c3994c81c34?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e6cd1c5be409b1e4bc8b8c3994c81c34?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Dark Reading","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Dark Reading","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/dr","url":"https://daily.dev/sources/dr"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/lorem-ipsum-malware-pivots-to-clickfix-delivery-oe9802vrx","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,wordpress,malware,ransomware","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Dark Reading","item":"https://daily.dev/sources/dr"},{"@type":"ListItem","position":3,"name":"'Lorem Ipsum' Malware Pivots to ClickFix Delivery"}]}
```

