SecureLeaf sinkhole telemetry surfaced two previously untracked lure domains funnelling victims into the known Omegatech ClickFix cluster. Detonation (ANY.RUN) and static analysis of the delivered stages confirm this is a delivery- and loader-layer revision — V13.1 — of the family tracked since V8, not a new malware family. The Donut MZER polyglot fingerprint and embedded .NET socket payload are intact; only the cradle path, PowerShell flags, lure fronts, and one C2 IP have changed.
Primary pivot: the native first-stage downloader (my_enterprise.bin, SHA-256 da3ba493…55503dc) is byte-identical across both lures and unchanged since 2026-07-16. Any host serving that stub belongs to this operator. Use it as the highest-confidence cluster indicator.
Verdict: SL-ADV-2026-V13.1 — delivery + loader revision, same family. No full teardown warranted; payload family unchanged.
ASN reconciliation: ANY.RUN enrichment tags the backend IPs OMEGATECH-AS, while ET/Spamhaus DROP rules fired on AS214943 RAILNET. SecureLeaf's route monitor (RIPEstat, 15-min cadence) resolves this: AS202412 is the BGP origin; RAILNET is assessed as upstream transit / DROP-list artifact, not the originating AS.
SecureLeaf's ASN Route Monitor (RIPEstat, 15-min cadence) independently ties every V13.1 network indicator to a single originating AS. All three IoC-bearing IPs sit inside currently-announced AS202412 /24s, verified live at 2026-07-25T05:54Z:
Indicator
Parent /24
Announced
Status
158.94.211.92 (C2/cradle)
158.94.211.0/24
2026-06-15
live ✓
91.92.243.161:3038 (2nd-stage C2)
91.92.243.0/24
2026-06-15
live ✓
178.16.53.137 (injector)
178.16.53.0/24
2026-06-15
live ✓
Watch space:94.154.46.0/24 is the only new prefix since the 2026-06-15 bulk bring-up (announced 2026-07-19). Not yet tied to any V13.1 IoC — flagged as anticipated-hostile pre-positioned space (likely next-wave/V14). Companion event: 45.74.59.0/24 withdrawn 2026-07-09. AS202412 rotates roughly one /24 per ~10 days.
20 prefixes announced by AS202412 (Omegatech Ltd, SC) as of report: 130.12.180.0/24, 146.19.125.0/24, 158.94.208.0/24, 158.94.209.0/24, 158.94.210.0/24, 158.94.211.0/24, 178.16.52.0/24, 178.16.53.0/24, 178.16.54.0/24, 178.16.55.0/24, 193.30.241.0/24, 45.132.180.0/24, 45.74.7.0/24, 91.92.240.0/24, 91.92.241.0/24, 91.92.242.0/24, 91.92.243.0/24, 94.154.35.0/24, 94.154.46.0/24, 94.26.38.0/24. Monitor caveat: change log is RIPEstat-timeout-heavy; 15-min cadence is not gap-free — a second source (RouteViews / bgp.tools) recommended as 502 fallback.
6 · MITRE ATT&CK
T1204.004 — User Execution: ClickFix (clipboard PowerShell)
T1102 — Web Service: EtherHiding via BSC testnet contract
Highest-signal single hunt: the shared downloader hash da3ba493…. Network-side, alert on cleartext GET /?sid=<ms>-<rand> to a dotted-quad with a powershell User-Agent, and on handleCmdCheck_ JSONP callbacks. Host-side, the MZER magic at offset 0 is a reliable Donut-family flag across V8–V13.1. Full rules in the accompanying YARA bundle.