The delivery path is the break. Blocking fake Teams download portals no longer covers the risk when the lure now lives on a compromised WordPress page and reaches ordinary visitors who never went looking for a download. The campaign is shifting from a narrow installer scam to a drive-by social-engineering pattern built around user-run PowerShell. BlueVoyant says the Lorem Ipsum operators dropped their signed Trojanized Microsoft Teams installers after Microsoft disrupted Fox Tempest and revoked more than 1,000 fraudulently obtained Microsoft Trusted Signing certificates. The new lure is a ClickFix prompt hosted on compromised WordPress sites, which widens exposure from people chasing a fake installer to anyone browsing those pages. The activity is now tracked with possible ties to Vice Society. That pivot matters because it removes the code-signing dependency and pushes the campaign onto ordinary web infrastructure. Public sites are no longer just victims here; they are the delivery layer.
Part of the PlainSec briefing for 2026-06-17