SEVERITY: HIGH TLP:CLEAR SL-ADV-2026-V13.1

Omegatech ClickFix → EtherHiding → DonutLoader — Delivery Revision V13.1

Two new lures (tapviaspace.com, hi8.one) confirmed on one shared V13.1 backend.
Advisory: SL-ADV-2026-V13.1 Published: 2026-07-25 Actor: AS202412 Omegatech Ltd, SC Family: ClickFix / ClearFake / DonutLoader Author: Dispensight · secureleaf.dispensight.com

1 · Executive summary

SecureLeaf sinkhole telemetry surfaced two previously untracked lure domains funnelling victims into the known Omegatech ClickFix cluster. Detonation (ANY.RUN) and static analysis of the delivered stages confirm this is a delivery- and loader-layer revision — V13.1 — of the family tracked since V8, not a new malware family. The Donut MZER polyglot fingerprint and embedded .NET socket payload are intact; only the cradle path, PowerShell flags, lure fronts, and one C2 IP have changed.

Primary pivot: the native first-stage downloader (my_enterprise.bin, SHA-256 da3ba493…55503dc) is byte-identical across both lures and unchanged since 2026-07-16. Any host serving that stub belongs to this operator. Use it as the highest-confidence cluster indicator.

2 · Attribution & version verdict

SignalFindingStatus
MZER polyglot header4D 5A 45 52 + Donut PIC bootstrap (E8 00 00 00 00 59 48 83 E9 09) on all stages✓ intact
Donut .fptable sectionPresent in both loaders✓ intact
Embedded .NET payloadBSJB metadata @0x2aaf4, System.Net.Sockets (socket RAT stage)✓ intact
Downloader stubByte-identical across lures; compiled 2026-07-16✓ shared
.NET loadersRecompiled per wave — tapviaspace 05:24:18Z, hi8 05:27:18Z (3 min apart)△ per-wave
Cradle/?sid=<ms>-<rand> (root path; /std/ dropped), + -UseBasicParsing△ revised
Verdict: SL-ADV-2026-V13.1 — delivery + loader revision, same family. No full teardown warranted; payload family unchanged.
ASN reconciliation: ANY.RUN enrichment tags the backend IPs OMEGATECH-AS, while ET/Spamhaus DROP rules fired on AS214943 RAILNET. SecureLeaf's route monitor (RIPEstat, 15-min cadence) resolves this: AS202412 is the BGP origin; RAILNET is assessed as upstream transit / DROP-list artifact, not the originating AS.

3 · Kill chain (observed)

4 · Indicators of Compromise

Network

IndicatorTypeNotes
158.94.211.92C2 / cradleCradle host + JSONP beacon. HTTP:80 stages, HTTPS:443 beacon. AS202412.
digitalenterprise2026.comC2 domainJSONP command-check → 158.94.211.92
91.92.243.161:3038C2 (2nd stage)Win32/Generic Agent C2 from injected svchost. AS202412.
dntds.shop / 178.16.53.137injectorClearFake/tdsshop jsrepo. AS202412.
tapviaspace.comlureCloudflare 104.21.96.34 / 172.67.172.64. Pixel 702732439530159.
hi8.onelureSame backend. ZeroSSL/Sectigo cert chain.
hash1.atpnd.commfallbackUnresolved fallback/DGA node (no answer during capture).

Host / file

FileSHA-256Role
my_enterprise.binda3ba493a8d5d48e42c0fb62e608163951479cef367d378a245c2c4fe55503dcdownloader — shared pivot
my_sss.binfa07519b1411539d84da7324e8e8d792462ce405e31ee160bb9b096b99bb48a6.NET loader (tapviaspace)
my_sss_hi8.bin4bd775f1f9e596b06238e63caa8b1ecb824be57e067dfb9102261ecd36a30afa.NET loader (hi8)

Cradle sids observed: 1784957071884-ogwj8ts2, 1784957071175-vjl9aezf (tapviaspace) · 1784957235640-yy9dpftt (hi8)

5 · Origin AS — BGP confirmation

SecureLeaf's ASN Route Monitor (RIPEstat, 15-min cadence) independently ties every V13.1 network indicator to a single originating AS. All three IoC-bearing IPs sit inside currently-announced AS202412 /24s, verified live at 2026-07-25T05:54Z:

IndicatorParent /24AnnouncedStatus
158.94.211.92 (C2/cradle)158.94.211.0/242026-06-15live ✓
91.92.243.161:3038 (2nd-stage C2)91.92.243.0/242026-06-15live ✓
178.16.53.137 (injector)178.16.53.0/242026-06-15live ✓
Watch space: 94.154.46.0/24 is the only new prefix since the 2026-06-15 bulk bring-up (announced 2026-07-19). Not yet tied to any V13.1 IoC — flagged as anticipated-hostile pre-positioned space (likely next-wave/V14). Companion event: 45.74.59.0/24 withdrawn 2026-07-09. AS202412 rotates roughly one /24 per ~10 days.

20 prefixes announced by AS202412 (Omegatech Ltd, SC) as of report: 130.12.180.0/24, 146.19.125.0/24, 158.94.208.0/24, 158.94.209.0/24, 158.94.210.0/24, 158.94.211.0/24, 178.16.52.0/24, 178.16.53.0/24, 178.16.54.0/24, 178.16.55.0/24, 193.30.241.0/24, 45.132.180.0/24, 45.74.7.0/24, 91.92.240.0/24, 91.92.241.0/24, 91.92.242.0/24, 91.92.243.0/24, 94.154.35.0/24, 94.154.46.0/24, 94.26.38.0/24. Monitor caveat: change log is RIPEstat-timeout-heavy; 15-min cadence is not gap-free — a second source (RouteViews / bgp.tools) recommended as 502 fallback.

6 · MITRE ATT&CK

T1204.004 — User Execution: ClickFix (clipboard PowerShell)
T1102 — Web Service: EtherHiding via BSC testnet contract
T1620 — Reflective Code Loading: Donut in-memory .NET
T1583.006 — Acquire Infrastructure: TDS (tdsshop/ClearFake)

7 · Detection notes

Highest-signal single hunt: the shared downloader hash da3ba493…. Network-side, alert on cleartext GET /?sid=<ms>-<rand> to a dotted-quad with a powershell User-Agent, and on handleCmdCheck_ JSONP callbacks. Host-side, the MZER magic at offset 0 is a reliable Donut-family flag across V8–V13.1. Full rules in the accompanying YARA bundle.

8 · Companion artifacts

FilePurpose
SL-ADV-2026-V13.1_bundle.jsonSTIX 2.1 bundle (11 indicators, malware, ATT&CK patterns, relationships)
SL-ADV-2026-V13.1.yarYARA bundle (5 rules — polyglot, loader, downloader, cradle, cluster domains)