The PowerShell is very different this wave — delivery re-tooled to a silent msiexec remote-MSI install — but every durable anchor holds: the RSA-1024 CAPI C2 handshake key fired in process memory, the C2/stage IP 158.94.211.92 is reused, and the new MSI host sits inside AS202412. A v15.0 label should be reserved for a break in the durable C2 key or code prologue — which did not occur here.
On 2026-08-24 a fresh detonation of the WP-002 chain was captured from the compromised Israeli lure host gbcu.org.il. The victim was steered through a ClickFix clipboard-paste overlay whose client stage (/mpackage.js, a ~132 KB VM-obfuscated JavaScript) plants a silent remote-MSI command:
This replaces the v14.9 IRM → password-ZIP → build.exe path with an msiexec LOLBIN (T1218.007) pulling the payload MSI over HTTPS. Three victim sessions were observed (1787536535958-i0cxy4o51787536610190-oqlgj67r1787536664828-xhrcamir); the last was leaked verbatim into Edge's Bing "parachute" search telemetry, confirming the clipboard-paste vector.
Only stages up to and including the MSI delivery + EtherHiding contact were observed on the wire. The final stage is greyed as inferred.
| Signal | v14.10 baseline | Verdict |
|---|---|---|
| Durable RSA-1024 CAPI C2 key modulus SHA-256 dc4cb858…febfac6f, e=65537 | Fired in process memory (deployed ClickFix-v8 signature hit) | UNCHANGED — dispositive |
| C2 / stage IP | 158.94.211.92 (AS202412, 158.94.211.0/24) — via cdn.claritydelivr.com | REUSED cross-wave |
| Hosting ASN | MSI host 91.92.240.194 ∈ AS202412 91.92.240.0/24 | SAME dependency |
| EtherHiding bootstrap | BSC-testnet RPC contacted | CONSISTENT |
| Victim token grammar | sid=<epoch-ms>-<8char> | CONSISTENT |
| ClickFix-v8 SHA1 anchor | 91A9773E…C674C3E0 | MATCHED |
| Delivery mechanism | msiexec remote-MSI /qn (was IRM→ZIP→build.exe in v14.9) | CHANGED — wave-level |
| Front / stage domains | cloudfrontenterprise.com · cdn.claritydelivr.com (new) | ROTATED — expected |
| Stage filename / form | mpackage.js — 132 KB VM-obfuscated JS (new) | CHANGED — wave-level |
| MSI host domain (v14.12) | cloudsenterprise2026.com — same IP 91.92.240.194 | ROTATED again — expected, IP anchor held |
| Raw C2 socket (v14.11→v14.12) | 158.94.208.92:61120 | CONFIRMED cross-wave — new durable anchor |
| Persistence tail (v14.11→v14.12) | CLIQuery\ + memu.exe | UNCHANGED — new durable path pivot |
Delivery re-tooling and domain rotation are exactly what a wave does; the cryptographic identity is what a family is. Every durable anchor has held across three consecutive waves (v14.10→v14.12), so this is still filed as v14.x, currently v14.12.
| Indicator | Resolved | Role | Handling |
|---|---|---|---|
| gbcu.org.il | 107.6.176.102 | ClickFix lure (compromised) | VICTIM — do NOT blocklist (splitcam) |
| cdn.claritydelivr.com | 158.94.211.92 | Stage/JS (mpackage.js) → durable C2/stage IP | Block / hunt |
| cloudfrontenterprise.com | 91.92.240.194 | MSI delivery host (CloudFront masquerade) | Block / hunt |
| 158.94.211.92 | AS202412 · 158.94.211.0/24 | Durable cross-wave C2/stage IP | Block / hunt |
| 91.92.240.194 | AS202412 · 91.92.240.0/24 | MSI host IP | Block / hunt |
| bsc-testnet-rpc.publicnode.com | 104.20.24.117 | EtherHiding read layer | ABUSED-LEGIT — record only |
| cdnjs.cloudflare.com | 104.17.24.14 / .25.14 | Legit CDN (JS) | Benign — do not block |
| Pivot | Value |
|---|---|
| RSA-1024 C2 key (modulus SHA-256) | dc4cb85885ffcf7bfa6f37c8ac4a8334a9504c06df0307a599c67ee2febfac6f · e=65537 |
| ClickFix-v8 PS-stage SHA1 anchor | 91A9773E7A0BA4700195CBFFFF935A24C674C3E0 |
| MZER + GetPC prologue (offset 0) | 4D 5A 45 52 E8 00 00 00 00 59 48 83 E9 09 |
| Native downloader imphash | 8e7b065c967657cca657d11206f96e23 |
| CLR loader imphash | edc8ef44e1870aad7a3e58dab17f8e1b |
| Tactic | Technique | ID | Evidence |
|---|---|---|---|
| Initial Access | Drive-by / compromised site | T1189 | gbcu.org.il lure |
| Execution | Malicious Copy & Paste (ClickFix) | T1204.004 | clipboard paste-run overlay |
| Execution | PowerShell | T1059.001 | PS → msiexec hand-off |
| Execution / Def-Evasion | System Binary Proxy: Msiexec | T1218.007 | msiexec /i http… /qn |
| Defense Evasion | Obfuscated Files or Information | T1027 | VM-obfuscated mpackage.js |
| Command & Control | Web Service (EtherHiding) | T1102 | BSC-testnet RPC |
| Discovery | Browser Information Discovery | T1217 | observed |
| Discovery | Query Registry | T1012 | observed |
| Discovery | System Information Discovery | T1082 | observed |
| Discovery | System Time Discovery | T1124 | observed |
| Defense Evasion | DLL Side-Loading | T1574.002 | observed (v14.11 §7.2, v14.12 §8.1 — host app rotates) |
| Defense Evasion / Priv Esc | Process Hollowing | T1055.012 | observed (v14.11 §7.1) |
| Command & Control | Non-Standard Port | T1571 | observed (v14.11 + v14.12, 158.94.208.92:61120 — durable) |
| Persistence | Scheduled Task | T1053.005 | observed (v14.12, TaskScheduler COM API, all 4 profiles) |
| Collection | Screen Capture | T1113 | memory-confirmed (v14.13 §9.2, CopyFromScreen/Bitmap) |
| Collection / Exfiltration | Archive/Encrypt Data | T1560 | memory-confirmed (v14.13 §9.2, AesManaged/CryptoStream) |
| Defense Evasion | Dynamic API Resolution / Reflective Loading | T1027.007 | memory-confirmed (v14.13 §9.2, AssemblyBuilder/DefineDynamicAssembly) |
This detonation ran the same lure to completion with a decryption-secrets block (TLS keylog) embedded in the capture, letting every TLS session on the wire be decrypted after the fact — including the MSI body itself. Findings below are extracted directly from the decrypted pcap and cross-validated byte-for-byte against the sandbox's own dropped-file hashes.
| File | Role | SHA-256 |
|---|---|---|
| e5a76bb.msi / MSI6AC1.tmp | Installer (WiX-built) | 38495f0d0aeb17e43da468e7d8befe470b64cf460ed993d06057ad13e09223fa |
| WorksFusion16.exe | Sideload host — legitimately signed PFU "SP Series Online Update" (orig. SpUpdater.exe), renamed | 66311b8e248cfb47f0ef29e48a996c03e25f9dd2ae1cd8d7289710d6a5459dcc |
| SsUCommon.dll | Malicious payload — UNSIGNED, spoofs the genuine PFU export table (41 exports) | 4d3fc09569f76eb2d16d7f880284e218481ed6ac0ada0592a53b71e8ed683809 |
| covrun32.dll | Legit-signed decoy (MS Visual Studio Code Coverage Runtime) | 6b3f04318d3d5fd0074227eeb99f00a05b56fd0ad331a6489fb7314b5ffcf51b |
| ucrtbase.dll | Legit-signed decoy (MS C Runtime) | b59c1f7e457b144a211b74b31492a68a7844232121c4046c7538b0d2ab3cfc31 |
| msvcp_win.dll | Legit-signed decoy (MS C Runtime) | 7a3d3b2dd5dbc304a1b0536ef0f9a41922e9ce06a25e9914a36d3160ba1f3d40 |
None of the five on-disk PEs carry the durable MZER+GetPC prologue or either durable imphash (8e7b065c… / edc8ef44…). Consistent with those cross-wave anchors living only in the memory-resident CLR stage reached via the injection chain above — not in the on-disk sideload kit. Sandbox family tags for this sample: HijackLoader / IDAT loader / Ghostulse — a tooling-level observation, not a change to attribution (still infrastructure-level, unattributed).
Characterized for the first time in this run: the lure page's client JS polls the stage host roughly every 3 seconds —
Twenty-one polls returned executed:false before the twenty-second flipped to executed:true — the backend tracks, per victim session id, whether the pasted msiexec command actually ran, independent of MSI delivery. This is a distinct, high-fidelity detection surface from the MSI/domain IOCs already tracked.
| Pivot | Value | Status |
|---|---|---|
| Raw AES C2/exfil socket | 158.94.208.92:61120 | NEW — same AS202412 /24 block as 158.94.211.92; provisional cross-wave anchor pending 2nd-wave confirmation |
| ClickFix status-poll pattern | /js-status?callback=handleCmdCheck_…&sid=… | NEW — endpoint/callback naming specific to this cluster |
| Sideload host binary | PFU "SP Series Online Update" (SpUpdater.exe) | NEW — single-sample, provisional |
| Sideloaded payload DLL | SsUCommon.dll (unsigned, spoofed exports) | NEW — single-sample, provisional |
Two further detonations of the same lure (tria.ge 260827-cl6tqswzgs, 4 sandbox profiles) landed shortly after v14.11. The headline: one v14.11 "provisional" anchor is now durable, one new technique appeared, and the sideload kit rotated again while its persistence tail did not.
| Anchor | v14.11 status | v14.12 finding | Verdict |
|---|---|---|---|
| 158.94.208.92:61120 | Provisional (1 wave) | Reconfirmed live in behavioral1.pcapng — identical 4-byte length-prefixed framing, different frame sizes | PROMOTED — durable |
| C:\ProgramData\CLIQuery\ + memu.exe | Observed once | Byte-identical name and path in this wave, despite everything around it rotating | PROMOTED — strongest current path pivot |
| MSI host domain | cloudfrontenterprise.com | cloudsenterprise2026.com | ROTATED — expected; IP 91.92.240.194 unchanged |
| Stage domain/IP | cdn.claritydelivr.com / 158.94.211.92 | Unchanged | UNCHANGED — 3rd wave running |
| js-status backend poll | handleCmdCheck_<ts>_<n>&sid=… | Unchanged, same grammar | UNCHANGED |
| Sideload host binary | PFU "SP Series Online Update" (SpUpdater.exe) | Unidentified Qt-based app | ROTATED — different legit app abused entirely |
| Sideload staging folder | %TEMP%\Inflow\ | %APPDATA%\Trypaflavine\ | ROTATED |
| Persistence technique | Self-copy + process injection only | + Scheduled Task via TaskScheduler COM API | NEW — T1053.005 |
Sandbox note: all four v14.12 profiles ran the lure through Firefox (-osint -url) rather than Chrome — most likely a sandbox-side choice, but it confirms the ClickFix chain isn't Chrome-specific. desktop.ini touches under Documents/Public in the report are attributable to Firefox itself, not flagged as malicious.
Full process memory dumps from the same 260827-cl6tqswzgs run (behavioral1: PIDs 5244, 5384, 4640, 2240, 1728; behavioral2: PID 3108) let us move several long-standing signature descriptions into direct evidence. A third archive, initially suspected to hold keys/certs relevant to the campaign, turned out to be unrelated.
PID 5384 — the process injected via SetThreadContext from the CLIQuery-resident sideload host — contains a reflectively-loaded assembly whose .NET Base Class Library API strings directly confirm capabilities the Triage signature descriptions have carried since the earliest v14.x reports:
| Signature description (previously inferred) | Memory evidence (now confirmed) |
|---|---|
| GDI screen capture | CopyFromScreen, Bitmap, ImageFormat, Encoder |
| AES CryptoStream exfil | AesManaged, CipherMode, CreateEncryptor, CreateDecryptor, CryptoStream |
| Raw TcpClient exfil | TcpClient | (+ WebClient/DownloadString as an HTTP fallback channel, not previously documented)
| "CLR-hosted" | CorBindToRuntime, CLRCreateInstance, CorExitProcess | — the native loader manually hosts the CLR rather than being a normal managed EXE
| "Reflective assembly" | AssemblyBuilder, DefineDynamicAssembly, DefineDynamicModule, System.Reflection.Emit | — runtime IL emission, matching the technique name exactly
Local variable/field names in this payload are short randomized tokens (unit34, wave26, wrap02, wrk112, pipe410, vec84, and similar) that clearly rotate per build — not usable as durable strings. The new YARA rule (§9.4) targets the BCL API names instead, which the payload cannot rotate away without breaking functionality.
PID 1728 (behavioral1) and PID 3108 (behavioral2) both contain a genuine, fully-parseable .NET DLL with a valid CLR header — but its class/method names (AddNamesInInheritanceHierarchy, AnonymousTypeDisplayClass, and other C#/VB symbol-table internals) identify it as the .NET Framework's own C#/VB compiler service, not the payload. Almost certainly present because the ClickFix PowerShell stage uses Add-Type to dynamically compile inline C# — consistent with the long-standing "ClickFix v8 — PowerShell stage: PSReadLine + .NET + RSA key in process memory" signature. Identical in both behavioral captures, byte-for-byte in the regions checked.
WP002_CLR_infostealer_capability_fingerprint_v14_13 — requires 2 of the screen-capture strings, 2 of the AES strings, 1 network string, 1 CLR-hosting string, and 1 reflective-assembly string in the same scanned region. Intended for memory/process scanning (Sysmon+YARA, Moneta, Hollows Hunter, or an EDR memory-scan feature) rather than static file scanning of the small native stub loaders, which don't carry these strings themselves.