PULSE NAME
Lorem Ipsum Malware: Trojanized MS Teams Installers
WHITE AlienVault 2026-05-04 Modified: 2026-05-05
13
IOCs
MEDIUM VOLUME
An emerging threat group is conducting a global SEO-poisoning campaign distributing trojanized Microsoft Teams installers that deploy a multi-stage shellcode loader and backdoor designated Lorem Ipsum. Active since February 2026, the campaign targets users searching for Microsoft Teams across six countries, with confirmed targeting of a US healthcare organization. The operators evolved rapidly from minimally obfuscated test builds to sophisticated loaders featuring substitution cipher decoding, XOR-encrypted shellcode, DLL sideloading, and JFIF-disguised C2 traffic. The malware distinctively abuses letsdiskuss[.]com, a legitimate India-based platform, as a dead-drop resolver for C2 infrastructure. Attackers use validly signed MSI installers with three-day Microsoft ID Verified certificates, NameCheap-registered infrastructure weaponized within hours, and per-victim UUID-tracked callbacks. Development velocity suggests possible LLM-assisted tooling, indicating a well-funded mid-tier criminal actor operating...
Indicators of Compromise (13)
All FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 045b76fa552dbfdfb7e5de66c9c599fe91151384be6a9849ec8965aa7251b818 2026-05-04
FileHash-SHA256 448afbdb6752c86e627d269ea244994d2c072d5110b490232dd7834943b043cb 2026-05-04
FileHash-SHA256 82ebca8612e203f6d8a2dcdc5e586095ebf94e5e29724ba92cd8bd090df47eb2 2026-05-04
FileHash-SHA256 ba5d73ca2c5aced43c7605e5652ba31fc63ca9b1f419ee4b934757c010c60f75 2026-05-04
URL https://official-teams-storage.com/files_dws_arch/MTSetup_v15.3.71194.msi 2026-05-04
URL https://www.letsdiskuss.com/user/dhuahsd12d2752 2026-05-04
domain biblegodlike.com 2026-05-04
domain graburban.com 2026-05-04
domain official-teams-storage.com 2026-05-04
domain reeeeealy.com 2026-05-04
domain semigoddess.com 2026-05-04
domain valeurban.com 2026-05-04
hostname www.letsdiskuss.com 2026-05-04