New 'TerminalFix' Scam Tricks Users Into Installing Hidden Malware via Windows Terminal
Security researchers at Sophos have identified a new twist on the well-known 'ClickFix' scam technique, which they call 'TerminalFix'. Instead of tricking victims into opening the Windows Run dialog, these lures instruct users to open a Windows Terminal window and run a command. That command downloads a ZIP file containing a legitimate Windows program, a malicious DLL, and a script that quietly installs persistence mechanisms on the victim's machine.
The malicious DLL loads a tool called Lorem Ipsum Loader, first documented by BlueVoyant earlier in 2026. This loader is designed to avoid detection by disguising its malicious code as ordinary English words rather than typical binary data, using a lookup table to convert the words back into executable instructions. Once running, it contacts a profile on a legitimate online platform to retrieve the addresses of its command and control servers, then communicates with them using web traffic disguised as JPEG image uploads.
Sophos has linked this activity to a broader campaign, tracked as STAC4924, that has been active since at least March 2026. While not attributed to a specific known threat group, the campaign has appeared across multiple intrusion attempts throughout the year, suggesting ongoing and evolving use of this technique.