PULSE NAME
Lorem Ipsum Malware: Trojanized MS Teams Installers
WHITE AlienVault 2026-05-04 Modified: 2026-05-05
13
IOCs
MEDIUM VOLUME
An emerging threat group is conducting a global SEO-poisoning campaign distributing trojanized Microsoft Teams installers that deploy a multi-stage shellcode loader and backdoor designated Lorem Ipsum. Active since February 2026, the campaign targets users searching for Microsoft Teams across six countries, with confirmed targeting of a US healthcare organization. The operators evolved rapidly from minimally obfuscated test builds to sophisticated loaders featuring substitution cipher decoding, XOR-encrypted shellcode, DLL sideloading, and JFIF-disguised C2 traffic. The malware distinctively abuses letsdiskuss[.]com, a legitimate India-based platform, as a dead-drop resolver for C2 infrastructure. Attackers use validly signed MSI installers with three-day Microsoft ID Verified certificates, NameCheap-registered infrastructure weaponized within hours, and per-victim UUID-tracked callbacks. Development velocity suggests possible LLM-assisted tooling, indicating a well-funded mid-tier criminal actor operating...
Indicators of Compromise (2 / 13 total)
All FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
URL https://official-teams-storage.com/files_dws_arch/MTSetup_v15.3.71194.msi 2026-05-04
URL https://www.letsdiskuss.com/user/dhuahsd12d2752 2026-05-04