SecureLeafby Dispensight

Threat intelligence and security testing for cannabis and regulated retail.

SecureLeaf tests the systems dispensaries depend on, detects investment fraud with a live API, and publishes free, TLP:CLEAR advisories on the campaigns it tracks.

Latest Updated October 4, 2026

ClickFix Variants B and C: elevated shells, chain-hopping EtherHiding, and a C2 pushed onto Spamhaus-DROP space

Two new iterations surfaced on compromised WordPress sites in late September. Lures now open an administrator PowerShell, a browser-side screenshotter reports every visit, and with its fronting burned the operator has fallen back to self-hosting on its own blocklisted network — where delivery is visibly breaking down.

  • Block nowentry-verifed-cdn[.]codes, helauth[.]com, cfsubs[.]com, asseload[.]com, 178.16.52.0/24
  • Hunt forElevated PowerShell opened from the Win+X menu that immediately runs a download cradle
  • Still openThe final clipboard command was not recovered in either capture

Campaign archive

Every published iteration of SL-ADV-2026-WP-001 and its WP-002 payload, newest first. Attribution is held at the infrastructure level; compromised lure sites are victims and are never blocklisted.

  1. V16+17

    Variants B and C — what we know so far New

    Consolidated update across both late-September iterations: elevated Win+X lures, EtherHiding on BSC-testnet and Polygon, browser-side screenshot exfil, and the C2 forced onto Spamhaus-DROP AS202412.

    Lure freightbook365[.]com, gogreenlightloans[.]com

  2. V17

    Variant C — Polygon EtherHiding and self-hosted C2 on AS202412

    C2 moves off Cloudflare-fronted stagers to entry-verifed-cdn[.]codes on 178.16.52.101 (Spamhaus DROP). The on-chain lookup failed in capture and only a numeric string reached the clipboard — delivery is degrading.

    Lure gogreenlightloans[.]com

  3. V16

    Variant B — elevated shell, failover loader, screenshot exfil

    Russian-localized fake Turnstile walks visitors to an administrator PowerShell. A three-domain failover loader feeds a TDS-gated clipboard stage, while an html2canvas screenshotter reports to helauth[.]com on every visit.

    Lure freightbook365[.]com

  4. V15.3

    Remus Stealer via ClickFix/EtherHiding — revised analysis

    Links the chain end to end, from a BSC-testnet EtherHiding lure through the AutoIt loader to the recovered native core (build B, 2026-08-28). Corrects five earlier statements; documents four AutoIt obfuscation layers and an NXDOMAIN sentinel check.

    Lure dorz[.]nl

  5. V15.2

    Remus Stealer — IExpress-SFX and AutoIt loaders replace Donut

    The delivery pipeline is rebuilt on IExpress-SFX and AutoIt, but the durable RSA-1024 C2 key (dc4cb858…febfac6f) is confirmed in memory across two detonations. New C2 209.38.82.72:9048 / cdire[.]shop verified from packet captures.

    Lure dorz[.]nl

  6. v14.3

    Gatekeeper TDS and dual-chain EtherHiding

    A bot-filtering gatekeeper TDS sits in front of the fake-Cloudflare overlay. Staging runs on Polygon-mainnet and BSC-testnet in parallel over XHR, WebSocket and web3 channels. Stealer screen capture and WMI recon confirmed at runtime.

    Lure verrerie-farinelli[.]com

  7. Aug 3

    2026-08-03 detonation wave and the two-branch model

    Five TLS-decrypted detonations confirm V13.1.2 lineage and two segregated delivery branches (root and /std/), each with its own BSC-testnet contract, both on 158.94.211.92.

    Lure wissmann.co.il, jerseys.co.ke, ibrahimstores.com, +2

    Full write-up

    TLP:CLEAR public edition — freely redistributable. Five pcapng detonations across compromised WordPress lures (wissmann.co.il, jerseys.co.ke, ibrahimstores.com, classroom.mindloops.org, andstudio.lt), TLS-decrypted from embedded keylogs. All confirmed V13.1.2 lineage — no 14.x drift. The campaign runs two operationally-segregated branches, distinguished at the network, binary, and blockchain layers: root (digitalenterprise2026.com · /jsrepo · /my_enterprise/ · BSC contract 0x7Fd85c09…E437) and /std/ (senterprise2026.com · /teamrepo · /std_enterprise/ · 0xFB448D46…D469d), both C2s on 158.94.211.92. Durable pivots hold: MZER+GetPC prologue at offset 0, loader imphash edc8ef44e1870aad7a3e58dab17f8e1b, downloader imphash 8e7b065c967657cca657d11206f96e23. Per-victim loader recompile (~60s pre-detonation) makes per-sample SHA-256 non-durable — imphash is the pivot. Lure hosts are compromised victims (do-not-blocklist).

    • 5-Lure Wave — TLS-Decrypted PCAP
    • Two-Branch Model (root · /std/)
    • Per-Branch BSC-Testnet EtherHiding Contracts
    • imphash edc8ef44 / 8e7b065c — Durable Pivots
    • V13.1.2 Continuation — No 14.x Drift
    • STIX 2.1 (38 obj) + YARA + Suricata + HTML
    • TLP:CLEAR — Freely Redistributable
  8. WP-002

    WP-002 payload — native loader and CLR-hosted .NET infostealer

    Static and runtime characterization of the two delivered payloads: an MZER-polyglot loader injecting into svchost.exe, and a CLR-hosted browser infostealer exfiltrating over AES-encrypted raw sockets.

    Lure —

    Full write-up

    TLP:CLEAR public edition — freely redistributable. Full static + dynamic (VirusTotal Jujubox runtime) behavioral characterization of the two payloads the WP-001 chain delivers. Stage 2 (my_enterprise, 50,688 B) is a native MZER-polyglot loader — token/integrity recon, process enumeration, and VirtualAllocEx/WriteProcessMemory/CreateRemoteThread injection into svchost.exe — pulling enterprise/my_sss.bin from 158.94.211.92. Stage 3 (my_sss, 275,968 B) hosts the CLR (mscoree!CLRCreateInstance) and reflectively loads a managed infostealer: browser credentials/cookies + local files + screenshots, AES-encrypted over a raw socket to a /c0g1k2s3 gate. Key runtime finding: both payloads are evasion-gated (IsDebuggerPresent, Sleep(60000) stall) and C2-dependent — neither completed its network stage under analysis, which is precisely why public sandbox scores understate them. IOC trap flagged: the Global\CLR_CASOFF_MUTEX mutex is a legitimate .NET artifact, not a campaign marker.

    • MZER Polyglot (4D 5A 45 52) — Cross-Version Anchor
    • Native Loader → svchost Injection
    • CLR-Hosted .NET Browser Infostealer
    • AES Socket Exfil (/c0g1k2s3 gate)
    • Evasion-Gated: Debugger Check + 60s Stall
    • CLR_CASOFF_MUTEX = False-Positive Trap
    • STIX 2.1 (68 obj) + YARA (5 rules) + HTML
    • TLP:CLEAR — Freely Redistributable
  9. V13.1.2

    Parallel root and /std/ delivery branches

    Two delivery templates with separate contracts, beacon domains and payload hosts share one C2. Loaders are now recompiled per victim within 60 seconds, and targeting widens to Australia, Estonia, Serbia and the US.

    Lure worrigeesports.com.au, munis-minibus.com, martvarauto.ee, besen-group.com

  10. V13.1

    Twin-lure delivery revision on one shared backend

    A byte-identical native downloader across both lures becomes the primary pivot; per-wave .NET loaders compile three minutes apart.

    Lure tapviaspace.com, hi8.one

    Full write-up

    TLP:CLEAR public edition — freely redistributable. Two newly surfaced lures — tapviaspace.com and hi8.one — confirmed via sinkhole telemetry and detonated (ANY.RUN) on a single shared V13.1 backend. Continuity is nailed at the byte level: the Donut MZER polyglot header (4D 5A 45 52) + PIC bootstrap and the embedded BSJB .NET socket payload are intact. Primary pivot: the native WinHTTP first-stage downloader (da3ba493…55503dc) is byte-identical across both lures and unchanged since 2026-07-16 — any host serving it belongs to this operator. The two my_sss .NET loaders are recompiled per wave, their timestamps clustering 3 minutes apart (05:24:18Z / 05:27:18Z) inside the live SID window. Cradle revised to root path /?sid=<ms>-<rand> with -UseBasicParsing; infra stapled to the cluster via 158.94.211.92, second-stage C2 91.92.243.161:3038, and injector dntds.shop. Assessed V13.1, not V14: delivery + loader wrapper revised, payload family unchanged.

    • Twin Lures (tapviaspace.com · hi8.one)
    • Byte-Identical Downloader = Shared Pivot
    • MZER Polyglot + BSJB .NET Intact
    • Per-Wave Loaders — 3 min Apart
    • New 2nd-Stage C2 (91.92.243.161:3038)
    • hi8 Broken TLS Leaks ZeroSSL/Sectigo CA
    • STIX 2.1 + OTX-Ready YARA + HTML
    • TLP:CLEAR — Freely Redistributable
  11. V13

    Per-victim server rebuild and on-host csc.exe compilation

    The outer loader is rebuilt server-side per victim and a second compile runs on the host; injected svchost.exe hosts CLR v2.0, predating AMSI .NET integration.

    Lure healthcare site (unnamed)

    Full write-up

    TLP:CLEAR public edition — freely redistributable. Continuity is again imphash-confirmed: the Donut/.NET loader still carries edc8ef44e1870aad7a3e58dab17f8e1b — identical to V12 and V12.1, the same source tree recompiled once more. New compromised lure site in the healthcare sector (victim, deliberately unnamed pending remediation — not blocklisted). New in this release: the outer loader is rebuilt server-side per victim — its compile timestamp postdates the visitor's own session ID by ~5m25s, reproduced across two sessions — and a second compilation runs on the victim host via PowerShell Add-Type/csc.exe, emitting a Rozena-style VirtualAlloc/CreateThread launcher with randomised names per run. Injected svchost.exe hosts CLR v2.0.50727, which predates AMSI .NET integration — visible in ordinary fusion logs. New C2 domain dntds.shop alongside the V12 node senterprise2026.com. Final-stage objective remains unresolved and no capability is claimed.

    • imphash edc8ef44… STILL IDENTICAL to V12
    • Loader Compiled AFTER Victim's Session ID
    • Second Compile On-Host via csc.exe
    • CLR v2.0 in svchost = AMSI Avoidance
    • New C2 dntds.shop
    • Lure = Healthcare Site (Victim, Unnamed)
    • TLP:CLEAR — Freely Redistributable
  12. V12.1

    Native MinGW stager and recycled V11 C2

    Imphash-identical .NET loader; a new MinGW-w64/GCC-15 WinHTTP downloader fronts it, and the V11 domain is recycled onto a new /24.

    Lure naturlexikon-bayern.de

    Full write-up

    V12.1 analysis from full detonation forensics (PCAP + live artifacts). Same unknown APT reusing AS202412 infrastructure (operator of record: Omegatech LTD — infra provider, not a confirmed actor identity). Continuity is imphash-confirmed: the Donut/.NET loader carries edc8ef44e1870aad7a3e58dab17f8e1b — byte-identical to V12, i.e. the same source tree merely recompiled. New compromised lure naturlexikon-bayern.de (a Bavarian nature encyclopedia run by a charitable foundation — victim, not attacker infra). New in V12.1: a native MinGW-w64 / GCC-15 WinHTTP downloader stage now fronts the .NET loader — a different toolchain entirely. Infra rotated to 158.94.211.92 (V12 used 158.94.208.104), and the V11 domain digitalenterprise2026.com was recycled onto it while still serving the V12 stage config — so Chain_V11 and Chain_V12 now fire simultaneously. The MZER polyglot Donut header returns, and the EtherHiding contract 0xFB448D…D469d (BSC testnet) is extracted for the first time. Assessed V12.1, not V13: the chain config and .NET core are unchanged.

    • imphash edc8ef44… IDENTICAL to V12
    • Native MinGW/GCC-15 WinHTTP Stager
    • V11 Domain Recycled onto New /24
    • MZER Polyglot Donut Header Returns
    • EtherHiding Contract Extracted (BSC)
    • Lure = Charity Site (Victim, Not Blocklisted)
    • STIX 2.1 + OTX-Ready YARA + HTML
  13. V12

    senterprise2026.com verification node

    A new C2 acts as an anti-replay verification node, stage 2 moves to /s_enterprise/, and eth_call is fully encoded — closing a YARA gap.

    Lure ejecutivos.es

    Full write-up

    V12 analysis from PCAP forensics and live-artifact triage. Attributed to an unknown APT reusing AS202412 infrastructure (operator of record: Omegatech LTD — infra provider, not a confirmed actor identity). New compromised WordPress lure ejecutivos.es; a new C2 domain senterprise2026.com acts as a verification / anti-replay node (confirmChallenge SID tracking). Stage-2 renamed /s_enterprise/ (was /my_enterprise/) and eth_call is now fully encoded in the string-array — closing the cleartext-eth_call YARA gap. Infra stays stapled to the cluster (158.94.208.104 · 91.92.240.121 · 178.16.53.137); fresh .NET Donut loader compiled 2026-07-07.

    • New Lure (ejecutivos.es)
    • senterprise2026.com Verification Node
    • s_enterprise/ Stage-2 (was /my_enterprise/)
    • Encoded eth_call — YARA Gap Closed
    • Infra Reuse (AS202412) = Same Unattributed Actor
    • STIX 2.1 + YARA + HTML Bundle
  14. V11

    splitcam.com lure and the BSC-testnet shift

    EtherHiding moves from BSC mainnet to testnet; Donut-to-svchost injection re-confirmed, with Task Scheduler COM persistence on Windows 10.

    Lure splitcam.com

    Full write-up

    V11 campaign analysis from dual-VM (win10 + win11) tria.ge detonations and PCAP forensics. New compromised lure site splitcam.com; the EtherHiding contract read shifts from BSC mainnet to testnet, and the stage-2 path is renamed /my_enterprise/. Backend delivery stays constant on 158.94.208.0/24, keeping V11 stapled to the cluster. Donut → svchost.exe injection re-confirmed; win10 detonation adds Task Scheduler COM persistence.

    • New Lure (splitcam.com)
    • BSC Testnet EtherHiding
    • Infra Constant (158.94.208.0/24)
    • Donut → svchost Injection
    • Task Scheduler COM Persistence
    • STIX 2.1 + YARA Bundle (83 objects)
  15. V10

    New lure, reversion to V8 baseline infrastructure

    A new standalone EtherHiding loader, but post-EtherHiding infrastructure reverts exactly to V8 — undoing V9's YARA-evasion rotation.

    Lure jbhtech.org.il

    Full write-up

    V10 campaign analysis with PCAP forensics. A new standalone EtherHiding loader (css.js) is delivered from a new compromised lure site, jbhtech.org.il, but post-EtherHiding infrastructure reverts to V8's exact baseline — same PS C2 IP, same staging path, same tid naming — undoing V9's YARA-evasion rotation. Static analysis confirms the stage-3 Donut blob and stage-4 CLR-hosting payload remain structurally consistent with V8.

    • New Lure Site (jbhtech.org.il)
    • Infra Reversion to V8
    • Donut Blob Re-Confirmed
    • CLR-Hosting Payload Analysis
    • Supports SL-RETRACT-2026-001
  16. V9

    Infrastructure rotation and single-token YARA evasion

    Beacon and EtherHiding payload delivery split into separate stages; a surgical tid→sid rename defeats V8 rules. Browser-to-C2 in 26 seconds.

    Lure —

    Full write-up

    V9 campaign analysis with PCAP forensics. New architecture separates JS beacon from EtherHiding payload delivery. Introduces a surgical tid→sid mutation to defeat V8 YARA rules. Full compromise confirmed at 26 seconds.

    • RC4+Obfuscator.io Custom Obfuscation
    • Beacon / Payload Stage Split
    • Single-Token YARA Evasion
    • PCAP-Confirmed Forensics
    • STIX 2.1 Bundle (1,108 objects)
    • 26s Browser-to-C2 Chain
  17. V8

    Complete kill chain — in-memory shellcode

    Three-stage in-memory execution from fake Cloudflare lure to RWX thread injection with zero disk artifacts, about one second to compromise.

    Lure —

    Full write-up

    Full end-to-end kill chain analysis of the Omegatech ClickFix v8 campaign (AS202412, Seychelles BPH). Three-stage in-memory shellcode execution from fake Cloudflare lure to RWX thread injection — zero disk artifacts, ~1s to compromise. Includes PCAP-extracted loader, YARA rules, SIEM queries, and STIX 2.1 bundle.

    • In-Memory Shellcode (T1620)
    • Fake Cloudflare Lure
    • P/Invoke via Add-Type
    • YARA + SIEM Rules
  18. May

    Original whitepaper — ClickFix WordPress implant

    Where it started: static and behavioural analysis of the Shadow DOM implant and a secondary injector in a compromised WordPress install.

    Lure —

    Full write-up

    Full static and behavioural analysis of the ClickFix Shadow DOM JavaScript implant plus a secondary independent injector found in a compromised WordPress installation. Includes IOCs, deobfuscated payload breakdown, and remediation steps.

    • Shadow DOM Injection
    • Secondary JS Injector
    • Full IOC List
    • Remediation Guide

Fraud and vulnerability advisories

Investment scams, recruitment fraud and point-of-sale vulnerabilities, with takedown status. Neutralized domains are tracked on the neutralization tracker.

  • ADV-2025-001Critical · CVSS 9.8

    Cannabis POS system vulnerabilities

    Multiple critical vulnerabilities in cannabis point-of-sale systems. Immediate review recommended for affected operators.

  • ADV-2025-002Partially neutralized

    Clyra Capital — crypto pump and dump via WhatsApp

    Coordinated pump-and-dump targeting investors through WhatsApp groups. Primary domain neutralized via Client Hold.

  • ADV-2025-003Active threat

    BCBit / BCBitPro multi-domain crypto fraud network

    Investment scam impersonating legitimate platforms, recruiting via WhatsApp, Telegram, Facebook and Instagram.

  • ADV-2025-004Critical

    financeap.vip pig-butchering network

    21+ fraudulent endpoints impersonating Robinhood, Charles Schwab, JPMorgan and others. ML ensemble: 99.9% fraud confidence.

  • Task scamsActive threat

    Fake “task” job offers

    Scammers promise $5,000+ a month for simple online tasks. Recruitment pipelines, red flags, and how to verify a domain.

Fraud Detection API

Conservative pattern analysis confirmed by a machine-learning ensemble, tuned to catch scam messages without flagging legitimate conversations.

92%+ML accuracy
36ktraining samples
4models in the ensemble
Pig butcheringInvestment scamsRomance scamsRecovery scamsSE Asian syndicates

Why cannabis retail is a target

The industry carries risks that general-purpose security programs weren’t built for.

  • Cash and data in one place

    Cash-intensive operations, valuable customer data and limited banking access make dispensaries attractive targets.

  • Compliance you can lose a licence over

    Track-and-trace, seed-to-sale and record-keeping obligations leave a large digital footprint. Non-compliance can mean suspension or revocation.

  • Sensitive customer records

    Medical records, purchase histories and government IDs. A breach exposes customers to identity theft and destroys trust.

  • Unusual payment rails

    Limited banking pushes businesses toward alternative processors and fintech, each a new fraud surface.

  • A long supply chain

    Growers, distributors, testing labs and regulators all connect in. Your security is only as strong as your weakest vendor.

  • Connected grow operations

    Climate controls and IoT devices are insecure by default, and a compromise can cost a whole crop.

Services

Simulated attacks and continuous monitoring that find weaknesses before someone else does.

Penetration testing

Simulated attacks on your infrastructure.

  • Point-of-sale systems
  • E-commerce platforms
  • Track-and-trace systems
  • Wireless networks
  • Physical security

Red team operations

Adversary simulation that tests detection and response.

  • Social engineering
  • Multi-vector scenarios
  • Insider threat simulation
  • Supply chain compromise
  • Incident response validation

Vulnerability assessment

Scanning and analysis of your digital assets.

  • Network scanning
  • Web application testing
  • Mobile app review
  • IoT devices
  • Cloud configuration

Compliance security

Controls that meet regulatory and industry standards.

  • Provincial regulation
  • PCI DSS
  • HIPAA (medical)
  • Data protection audit
  • Security policy development

Security training

Help your team recognize and respond to threats.

  • Awareness training
  • Phishing simulations
  • Incident response drills
  • Secure coding
  • Executive briefings

Ongoing monitoring

Threat intelligence tailored to your sector.

  • 24/7 threat monitoring
  • Dark web monitoring
  • Fraud detection API
  • Vulnerability management
  • Incident response
  • Monthly reports

Talk to us before a breach does.

Book a free consultation, request API access, or report a campaign. Encrypted mail welcome — our PGP key is published.

Email secureleaf@dispensight.com