“Lorem Ipsum” Loader Weaponizing Microsoft Teams via SEO Poisoning
ID: 9a9344bf-d871-5ace-b201-8d8986ca2589
STIX ID: report--9a9344bf-d871-5ace-b201-8d8986ca2589
Feed Name: securityonline.info
BlueVoyant researchers describe a rapidly maturing, well-resourced SEO‑poisoning campaign that lures victims searching for Microsoft Teams to dropper installers signed with short-lived Microsoft-verified certificates; the installers deploy a multi-stage in-memory loader and backdoor called “Lorem Ipsum,” use DLL sideloading and XOR/substitution-decoded shellcode, disguise C2 as JFIF image files, and use a legitimate India-based platform as a dead-drop resolver. The group targets multiple countries (including a confirmed U.S. healthcare victim), exhibits high development velocity, and may be operating as an initial access broker selling persistent footholds to downstream actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
