SecureLeaf Advisory · SL-ADV-2026-WP-001 · V13.1.2

Omegatech ClickFix / EtherHiding / DonutLoader

A ClickFix → BSC-testnet EtherHiding → DonutLoader kill chain, now running two operationally-segregated delivery branches that are separated all the way down to the blockchain layer. Documented from four live detonations on 2026-08-01.

Published 2026-08-01 Threat level High Cluster AS202412 (Omegatech LTD) Contracts 2 · rotation-proof Actor Unattributed
ATTRIBUTION

Unknown intrusion set using AS202412 infrastructure. This advisory asserts only what the telemetry proves: every hostile hop is BGP-homed in AS202412 (Omegatech LTD, Seychelles bulletproof hosting). Confidence in the infrastructure linkage is high. No named-group, nation-state, or actor-identity attribution is made or implied — and none is warranted by the evidence in hand.

01

Summary

The cluster tracked since V8 as “Omegatech ClickFix” continues under the same kill chain: a compromised website reads a base64 JavaScript payload out of a BNB-Smart-Chain testnet smart contract (EtherHiding), presents a fake-verification ClickFix lure that pastes a PowerShell cradle, compiles a C# stub in memory (csc.exe/cvtres.exe), and runs a two-stage MZER-polyglot Donut loader that injects into svchost.exe and persists via a Task Scheduler COM object.

What is materially new in V13.1.2 is structural, not mechanical: the operator now runs two parallel delivery branches — a root template and a /std/ template — that share one C2 IP and one payload host but keep separate beacon domains, separate payload-host domains, and separate EtherHiding contracts. The branches are segregated down to the blockchain layer. Four lures detonated within a ~9-minute window on 2026-08-01 resolve cleanly into this one wave.

The durable takeaway: almost everything in this campaign rotates — sample hashes (recompiled per victim), fronting domains, lure sites. Two things do not: the two BSC contracts and the two loader/downloader imphashes. Detection and reporting should lead with those.

02

Kill chain

Identical across both branches; only the paths, domains, and contract differ.

01
Compromised site
WordPress / CMS lure
(victim host)
02
EtherHiding
eth_call get()
0x6d4ce63c → BSC testnet
03
ClickFix lure
clipboard → PowerShell
paste
04
PS cradle
irm/iex →
/?sid= or /std/?sid=
05
In-memory C#
csc.exe → cvtres.exe
<rand>.dll
06
Downloader
MZER · WinHTTP
imphash 8e7b065c
07
CLR-host loader
MZER · mscoree
imphash edc8ef44
08
Inject + persist
svchost.exe →
Task Scheduler COM
Command channel. After execution the loader polls a JSONP beacon roughly once per second: GET /?callback=handleCmdCheck_<epochms>_<seq>&sid=&id= answered by handleCmdCheck_<…>({"executed":false}). In all four detonations the channel sat idle — no hands-on-keyboard command was tasked.

03

Anchors vs. rotation

The operator recompiles the loader within about a minute of each victim hitting the cradle, which kills per-sample SHA-256 as a pivot. Track the invariants instead.

Does not rotate — report these

Rotation-proof anchors

  • EtherHiding contract · root0x7Fd8…E437
  • EtherHiding contract · /std/0xFB44…469d
  • Loader imphashedc8ef44…8e1b
  • Downloader imphash8e7b065c…6e23
  • MZER + GetPC prologue4D5A4552 E8…4883E909
  • eth_call selector0x6d4ce63c get()
Rotates — low-value / short-lived

Rotates constantly

  • Loader SHA-256per victim (≈60s recompile)
  • Lure sitescompromised, disposable
  • sid token<epochms>-<rand> per victim
  • Beacon / payload domains*enterprise2026 · *dntds.shop
  • Fronting IPwithin AS202412 space

04

Two operationally-segregated branches

Both branches ride the same C2 IP (158.94.211.92, AS202412) and the same payload host (178.16.53.137, NL), but are otherwise parallel — including a distinct EtherHiding contract each.

Attributeroot/std/
Cradle path/?sid=<ms>-<rnd>/std/?sid=<ms>-<rnd>
Stage directory/my_enterprise//std_enterprise/ · /enterprise/
Loader artifactmy_sss.binstudent_s.bin
JSONP beacon domaindigitalenterprise2026.comsenterprise2026.com
Payload host domaindntds.shopsdntds.shop
BSC EtherHiding contract0x7Fd85c09…E4370xFB448D46…469d
Lures (2026-08-01)munis-minibus.comworrigeesports.com.au · martvarauto.ee · besen-group.com
Shared spine: C2 158.94.211.92 · aux 158.94.208.92:61120 · payload 178.16.53.137 · downloader 8e7b065c · loader edc8ef44 · MZER/GetPC prologue · bsc-testnet.bnbchain.org primary with bsc-testnet-rpc.publicnode.com failover.

05

What's new versus earlier families

A calibrated diff against prior versions of the same cluster. Only genuine deltas are listed.

DimensionV8 – V13.1.1 (prior)V13.1.2 (this wave)
Delivery templatesSingle trackTwo concurrent branches (root + /std/)
EtherHiding contractsSingle contractOne contract per branch — segregated at the chain layer
Loader recompile cadencePer-wave (V13.1.1)Per-victim, ≈60s before detonation
Beacon / payload domainsprocess.iconnode.com; earlier hosts*enterprise2026.com beacons; dntds.shop / sdntds.shop payload repos (/jsrepo)
Stage-2 transportV11: cleartext HTTP cradleCleartext IP cradle and TLS domain beacon in parallel; MZER served over cleartext :80
Injector vectorShadow-DOM (V2); obfuscator.io inline (V13.1.1)Inline-HTML and jquery-migrate library-append both observed
Lure geographyUK / IL / FR / ME focusWidened: AU · EE · RS · US
Native chain shapeUnder-characterised second stageConfirmed two-stage: WinHTTP downloader (8e7b065c) → CLR-host loader (edc8ef44)

Consistent with prior versions (not new): the MZER polyglot header with GetPC bootstrap, the Donut/CLR-hosting architecture, the ClickFix→PowerShell→csc.exe in-memory compile, svchost injection, Task Scheduler COM persistence, BSC-testnet (not mainnet) EtherHiding, and the ipinfo.io geolocation check.

06

Detonations — 2026-08-01

Four samples, one wave. sid values are per-victim epoch-ms tokens; each decodes to its own detonation minute, confirming live per-victim tracking. All lure hosts are compromised victims.

Lure (victim)Geo / hostBranchsid → UTCLoader compiled
worrigeesports.com.auAU · 23.235.217.105/std/02:0x08-01 01:42:41
munis-minibus.comRS · 185.119.89.171root02:02:5008-01 01:42:41
martvarauto.eeEE · 185.7.252.210/std/02:07:3508-01 02:07:41
besen-group.comUS/GCP · 35.212.53.5/std/02:11:1908-01 02:10:41

07

Indicators

Rotation-proof — lead with these

TypeValueContext
BSC contract0x7Fd85c090f2b35071C57a3b9FeAF462aaEb0E437root · get() 0x6d4ce63c
BSC contract0xFB448D465841C63F3bC433be61Eb692b813D469d/std/ · get() 0x6d4ce63c
imphash (loader)edc8ef44e1870aad7a3e58dab17f8e1bCLR-host MZER loader
imphash (downloader)8e7b065c967657cca657d11206f96e23WinHTTP MZER downloader
byte prologue4D 5A 45 52 E8 00 00 00 00 59 48 83 E9 09 48 8BMZER + GetPC, both stages

Network — AS202412 & payload infrastructure

IndicatorRoleReport
158.94.211.92C2 / cradle + both beacon domainsblock
158.94.208.92:61120Aux stage host (AS202412)block
178.16.53.137Encrypted payload host (NL) — dntds.shop / sdntds.shop /jsrepoblock
digitalenterprise2026.comRoot JSONP beaconblock
senterprise2026.com/std/ JSONP beaconblock
dntds.shop · sdntds.shopPayload repos (root · /std/)block
172.111.246.0/24New AS202412 announcement (2026-08-01)monitor — not yet used

Behavioural

PatternDetail
callback=handleCmdCheck_<ms>_<seq>JSONP command-poll; response handleCmdCheck_<…>({"executed":false})
?sid=<13-digit ms>-<rand>Per-victim tracking token on cradle + beacon
/jsrepo?rnd=<float>&ts=<ms>Stage-2 payload fetch on dntds.shop / sdntds.shop
?ob=open-bridge/eventsInjector beacon on the compromised lure

08

Do-not-blocklist

Lure hosts are compromised victims. worrigeesports.com.au, munis-minibus.com, martvarauto.ee, besen-group.com and their IPs must not be blocklisted or reported as malicious infrastructure. Do not derive indicators from web-lure strings.
Abused-legitimate — spare: bsc-testnet.bnbchain.org and bsc-testnet-rpc.publicnode.com (public BSC RPC), ipinfo.io, and the Microsoft / Google / Meta / analytics telemetry seen in the captures. The malice is the contract read, not the RPC endpoint.
172.111.246.0/24 is a fresh AS202412 announcement observed 2026-08-01 but not used by any hop in this wave. Route it to monitoring / the advisory channel rather than an active blocklist until it is seen serving.

09

MITRE ATT&CK

TacticTechnique
Initial Access / ExecutionT1204.004 ClickFix · T1059.001 PowerShell · T1059.007 JavaScript
Defense EvasionT1027 Obfuscation · T1140 Deobfuscate · T1055 Process Injection · T1620 Reflective Code Loading
Command & ControlT1102 Web Service (EtherHiding + JSONP) · T1105 Ingress Tool Transfer
PersistenceT1053.005 Scheduled Task (COM)
DiscoveryT1614 System Location (ipinfo.io) · T1082 System Info · T1012 Query Registry

10

Detection

Full ruleset ships alongside this advisory as SL-ADV-2026-WP-001-V13.1.2.yar (6 rules) and …stix2.json. Highest-fidelity anchors:

Verified: the loader rule matched the CLR-host stages carved from both martvarauto.ee and besen-group.com; the downloader rule matched the WinHTTP stage from munis-minibus.com and both /std/ lures — with clean separation between the two.