Threats · 90 days ago
The delivery path is the break. Blocking fake Teams download portals no longer covers the risk when the lure now lives on a compromised WordPress page and reaches ordinary visitors who never went looking for a download. The campaign is shifting from a narrow installer scam to a drive-by social-engineering pattern built around user-run PowerShell.
BlueVoyant says the Lorem Ipsum operators dropped their signed Trojanized Microsoft Teams installers after Microsoft disrupted Fox Tempest and revoked more than 1,000 fraudulently obtained Microsoft Trusted Signing certificates. The new lure is a ClickFix prompt hosted on compromised WordPress sites, which widens exposure from people chasing a fake installer to anyone browsing those pages. The activity is now tracked with possible ties to Vice Society.
That pivot matters because it removes the code-signing dependency and pushes the campaign onto ordinary web infrastructure. Public sites are no longer just victims here; they are the delivery layer.
2 sources covering this story
ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures
ClickFix attacks are delivering BabaDeda, Lorem Ipsum, and Potemkin loaders to deploy stealers, RATs, and ransomware-linked tooling.
'Lorem Ipsum' Malware Pivots to ClickFix Delivery
New analysis shows the campaign, which uses compromised WordPress sites, may be linked to the ransomware and extortion group Vice Society.
Part of the PlainSec briefing for 2026-06-17