Cybersecurity Research

New 'TerminalFix' Scam Tricks Users Into Installing Hidden Malware via Windows Terminal

Sophos · 30 Sept 2026
Key Takeaway Train staff to be suspicious of any instructions that ask them to open Terminal, Run, or PowerShell and paste in a command, even if it appears to come from a trusted-looking source.

Security researchers at Sophos have identified a new twist on the well-known 'ClickFix' scam technique, which they call 'TerminalFix'. Instead of tricking victims into opening the Windows Run dialog, these lures instruct users to open a Windows Terminal window and run a command. That command downloads a ZIP file containing a legitimate Windows program, a malicious DLL, and a script that quietly installs persistence mechanisms on the victim's machine.

The malicious DLL loads a tool called Lorem Ipsum Loader, first documented by BlueVoyant earlier in 2026. This loader is designed to avoid detection by disguising its malicious code as ordinary English words rather than typical binary data, using a lookup table to convert the words back into executable instructions. Once running, it contacts a profile on a legitimate online platform to retrieve the addresses of its command and control servers, then communicates with them using web traffic disguised as JPEG image uploads.

Sophos has linked this activity to a broader campaign, tracked as STAC4924, that has been active since at least March 2026. While not attributed to a specific known threat group, the campaign has appeared across multiple intrusion attempts throughout the year, suggesting ongoing and evolving use of this technique.

malware ClickFix Sophos command and control social engineering

Summarised by CISO AI from Sophos. We link back to every original so you can read it yourself.