logo

“Lorem Ipsum” Loader Weaponizing Microsoft Teams via SEO Poisoning

ID: 9a9344bf-d871-5ace-b201-8d8986ca2589

STIX ID: report--9a9344bf-d871-5ace-b201-8d8986ca2589

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Ddos

...
...

BlueVoyant researchers describe a rapidly maturing, well-resourced SEO‑poisoning campaign that lures victims searching for Microsoft Teams to dropper installers signed with short-lived Microsoft-verified certificates; the installers deploy a multi-stage in-memory loader and backdoor called “Lorem Ipsum,” use DLL sideloading and XOR/substitution-decoded shellcode, disguise C2 as JFIF image files, and use a legitimate India-based platform as a dead-drop resolver. The group targets multiple countries (including a confirmed U.S. healthcare victim), exhibits high development velocity, and may be operating as an initial access broker selling persistent footholds to downstream actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.