$ techbeacon▋
Phishing

New Intrusion Set STAC4924 Exploits TerminalFix to Build Hidden Reverse Tunnels in Corporate Networks

New Intrusion Set STAC4924 Exploits TerminalFix to Build Hidden Reverse Tunnels in Corporate Networks

A previously undocumented intrusion group identified as STAC4924 has begun leveraging a tool called TerminalFix to deliver a malicious component known as the Lorem Ipsum Loader, creating concealed reverse tunnels that give attackers persistent access to corporate environments.

The operation relies on social‑engineering lures that appear to be legitimate TerminalFix updates or support messages. When a victim clicks the crafted link, the Lorem Ipsum Loader is silently installed, establishing an outbound tunnel that bypasses typical inbound firewall rules and allows the threat actors to control the compromised system from a remote server.

Security researchers note that this technique mirrors the earlier ClickFix campaign, which used the Windows Run dialog to execute malicious code. However, the latest variant shifts the initial execution point to other Windows interfaces, expanding the range of possible entry vectors and making detection more challenging for conventional endpoint defenses.

Reverse tunnels are a favored method among advanced threat actors because they do not require open listening ports on the victim network, reducing the likelihood of network‑based alerts. Once the tunnel is in place, the adversary can exfiltrate data, move laterally, or deploy additional payloads while remaining largely invisible to security monitoring tools.

The discovery was first reported by the independent security outlet GBHackers, which provided technical details that enabled several cybersecurity firms to issue advisories. Experts recommend that organizations scrutinize unexpected TerminalFix communications, enforce strict application whitelisting, and monitor for anomalous outbound traffic that could indicate a hidden tunnel.

While the full scope of the campaign remains under investigation, analysts warn that the adaptability of the STAC4924 group suggests future variations may target other Windows components. Continuous threat‑intel sharing and rapid patching of vulnerable software are seen as essential steps to mitigate the risk posed by this emerging intrusion set.

Source: GBHackers
Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related