← Back to Pulse Feed
PULSE DETAIL
An emerging threat group is conducting a global SEO-poisoning campaign distributing trojanized Microsoft Teams installers that deploy a multi-stage shellcode loader and backdoor designated Lorem Ipsum. Active since February 2026, the campaign targets users searching for Microsoft Teams across six countries, with confirmed targeting of a US healthcare organization. The operators evolved rapidly from minimally obfuscated test builds to sophisticated loaders featuring substitution cipher decoding, XOR-encrypted shellcode, DLL sideloading, and JFIF-disguised C2 traffic. The malware distinctively abuses letsdiskuss[.]com, a legitimate India-based platform, as a dead-drop resolver for C2 infrastructure. Attackers use validly signed MSI installers with three-day Microsoft ID Verified certificates, NameCheap-registered infrastructure weaponized within hours, and per-victim UUID-tracked callbacks. Development velocity suggests possible LLM-assisted tooling, indicating a well-funded mid-tier criminal actor operating...
MITRE ATT&CK & Malware Families
Indicators of Compromise (13)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA256 | 045b76fa552dbfdfb7e5de66c9c599fe91151384be6a9849ec8965aa7251b818 | — | 2026-05-04 | |
| FileHash-SHA256 | 448afbdb6752c86e627d269ea244994d2c072d5110b490232dd7834943b043cb | — | 2026-05-04 | |
| FileHash-SHA256 | 82ebca8612e203f6d8a2dcdc5e586095ebf94e5e29724ba92cd8bd090df47eb2 | — | 2026-05-04 | |
| FileHash-SHA256 | ba5d73ca2c5aced43c7605e5652ba31fc63ca9b1f419ee4b934757c010c60f75 | — | 2026-05-04 | |
| URL | https://official-teams-storage.com/files_dws_arch/MTSetup_v15.3.71194.msi | — | 2026-05-04 | |
| URL | https://www.letsdiskuss.com/user/dhuahsd12d2752 | — | 2026-05-04 | |
| domain | biblegodlike.com | — | 2026-05-04 | |
| domain | graburban.com | — | 2026-05-04 | |
| domain | official-teams-storage.com | — | 2026-05-04 | |
| domain | reeeeealy.com | — | 2026-05-04 | |
| domain | semigoddess.com | — | 2026-05-04 | |
| domain | valeurban.com | — | 2026-05-04 | |
| hostname | www.letsdiskuss.com | — | 2026-05-04 |