Five concurrent OTX pulses paint a single, coherent picture: credential theft at industrial scale, increasingly laundered through blockchain infrastructure and trusted software supply chains. This is not one campaign — it is a convergent ecosystem of access brokers and stealer operators who have collectively decided that smart contracts, browser extension stores, VPN gateways, and npm registries are more reliable delivery mechanisms than email ever was.
The most technically significant cluster is the EtherHiding / ClickFix convergence. Two independent operations — ClearFake (UAT-10820) delivering Amatera stealer, ZigCryptoStealer, and NetSupport Manager, and the PhantomPolia loader delivering Remus Stealer — both abuse public blockchain smart contracts (BNB Smart Chain and Ethereum Sepolia respectively) as dead-drop configuration stores. C2 domains are no longer in DNS; they are encrypted on-chain and resolved via public RPC endpoints like 1rpc.io/sepolia. This renders traditional domain takedown and DNS-sinkhole strategies largely ineffective against the configuration layer.
In parallel, the FortiBleed campaign has verified 86,644+ compromised FortiGate/SSL VPN devices across 194 countries, exploiting legacy SHA-256 password storage and reused credentials, cracked at scale with distributed GPU clusters (Hashtopolis). Verified VPN access is exactly the commodity that fuels initial access brokers feeding ransomware crews like INC/Lynx — which is already tagged in the pulse.
Rounding out the picture: 16 malicious Firefox extensions cloning Rabby and OKX wallet flows to harvest seed phrases, and the TensorLake npm SDK (v0.5.144) compromise — a ChainDrop/Shai-Hulud wormable supply-chain attack harvesting npm tokens, GitHub tokens, AWS keys, Vault secrets, Kubernetes configs, and SSH keys from ~12,000 weekly downloads. The objective across all five pulses is uniform: harvest every credential class — human, machine, and developer — and monetize it through access brokerage and direct crypto theft.
Threat Actor / Malware Profile
UAT-10820 / ClearFake → Amatera + ZigCryptoStealer + NetSupport Manager
- Distribution: Compromised websites injected with JavaScript via Cloudflare Workers; script itself is stored on BNB Smart Chain (EtherHiding). Victims see fake Google CAPTCHA / ClickFix prompts instructing them to run a "verification" command.
- Payload behavior: Two parallel infection chains; one loads a malicious DLL (
pf.ch) over WebDAV, sideloading Amatera stealer. Amatera harvests browser credentials, cookies, session tokens, and crypto wallet data. ZigCryptoStealer runs parallel wallet-draining logic. NetSupport Manager (legitimate RAT abused) provides hands-on-keyboard fallback access. - C2: Bulletproof-hosted domains such as
leaguejazire.com,smart.hugo-mapp.co,paf.hugo-mapp.co,tnt.unguidedfreewill.co. - Anti-analysis: On-chain config storage, WebDAV delivery to evade HTTP proxy inspection, CAPTCHA gating to block sandboxes, legitimate signed binaries (NetSupport) for defense evasion.
- Targeting: Government sector; US, Brazil, Egypt, India, Indonesia, Ukraine, BIOT.
PhantomPolia → Remus Stealer
- Distribution: ClickFix social engineering on compromised sites. PhantomPolia JS loader queries Ethereum Sepolia testnet smart contracts via public RPC (
1rpc.io/sepolia, Pocket Network endpoints). - Decryption: Configs decrypted locally with PBKDF2 + AES-GCM to derive C2 domains (
ironphantomcore.top,stormvenomforge.top,voidravenstorm.top,shadowemberstrike.top). - Execution: Victim pastes attacker-supplied PowerShell into Run dialog; retrieves Donut shellcode, which injects Remus Stealer in-memory; AutoIt scripts provide staging and persistence. Targets browser creds and cryptocurrency wallets.
- Anti-analysis: Testnet abuse (free, disposable), memory-only shellcode, local crypto key derivation defeats network-layer config interception.
FortiBleed (INC/Lynx-adjacent IAB operation)
- Vector: Internet-facing FortiGate firewalls / SSL VPN gateways; credential reuse + offline cracking of legacy SHA-256 password hashes via distributed GPU (Hashtopolis).
- Scale: 86,644+ verified compromised devices in 194 countries; harvesting infrastructure includes
103.27.186.156,154.202.59.169,45.154.12.132,80.75.212.113,193.8.187.2and others. - Monetization: Access sold/handled to ransomware affiliates (INC/Lynx); victims reporting admin lockouts indicate active post-compromise takeover.
Malicious Firefox Extensions (Raabby WaIIet / fake OKX)
- 16 extensions; four clone Rabby Wallet using homoglyph typosquatting ("Raabby WaIIet" with capital-I substitution), twelve impersonate OKX. Intercept recovery phrases and private keys during wallet import; exfil via Cloudflare Workers.
TensorLake npm SDK (ChainDrop / Shai-Hulud)
- Compromised version 0.5.144 with obfuscated postinstall credential harvester: npm tokens, GitHub tokens, AWS credentials, HashiCorp Vault tokens, kubeconfigs, SSH keys, AI tool credentials. Wormable persistence — stolen npm tokens are used to self-propagate into other maintainer packages.
IOC Analysis
The indicator set spans five operational categories, each requiring distinct handling:
- IPv4 (FortiBleed, 13 total): Credential-harvesting and scanning infrastructure. These are high-confidence blocklist candidates at the perimeter (firewall egress + VPN gateway ACLs), and should be retro-hunted against VPN authentication logs for the past 90 days — successful auth from these IPs means the credential is burned and the session must be treated as hostile.
- Domains/hostnames (ClearFake, PhantomPolia): Stealer C2 and staging (
*.hugo-mapp.co,*.unguidedfreewill.co,*.topPhantomPolia domains,leaguejazire.com). Block at DNS/sinkhole, but note the RPC endpoints (1rpc.io/sepolia, Pocket Network Sepolia API) are legitimate infrastructure — do not block outright; instead, alert on endpoint processes making JSON-RPC calls to blockchain testnets.verification.googleis a lookalike reference artifact, not a resolvable malicious host. - File hashes (Firefox extensions, TensorLake, ClearFake payloads, 100+ total): Push to EDR blocklists immediately. The two TensorLake hashes are the priority — presence in any
node_modulestree confirms compromise of developer machines and demands full secret rotation. - URLs (RPC endpoints): Treat as behavioral detections rather than blocks: legitimate developer workstations may query Sepolia; corporate endpoints running PowerShell-spawned RPC queries should not.
- Package version IOC:
tensorlake@0.5.144— audit lockfiles, private registries (Artifactory/Nexus caches), and CI artifacts. Version pinning audits catch what hash scanning misses.
Tooling: decode Donut shellcode configs with CyberChef + donut-decryptor; trace on-chain configs by querying the contract addresses via a local Sepolia/BSC node or BlockScout; OTX pulses ingest natively into MISP, OpenCTI, and Sentinel TAXII feeds.
Detection Engineering
---
title: ClickFix-Style WebDAV or Run-Dialog Payload Execution
date: 2026/10/08
id: 8f2c1a3e-clearfake-webdav-0001
status: experimental
description: Detects ClearFake/PhantomPolia ClickFix execution patterns - user-context processes spawning PowerShell or WebDAV-mapped DLL loads via rundll32, consistent with Amatera/Remus stealer delivery
author: Security Arsenal Threat Intel
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\explorer.exe'
- '\msedge.exe'
- '\chrome.exe'
- '\firefox.exe'
selection_child:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
- '\rundll32.exe'
- '\mshta.exe'
selection_args:
CommandLine|contains:
- 'WebClient'
- 'DownloadString'
- 'Invoke-Expression'
- 'IEX'
- '\\' # UNC path for WebDAV delivery
condition: selection_parent and selection_child and selection_args
falsepositives:
- Admin scripts executed manually
level: high
tags:
- attack.t1059.001
- attack.t1204.002
- attack.t1105
---
title: Endpoint Querying Blockchain RPC Testnet Endpoints
date: 2026/10/08
id: 9a3d7b2f-etherhiding-rpc-0002
status: experimental
description: Detects EtherHiding technique where PhantomPolia/ClearFake loaders resolve C2 configs from Ethereum Sepolia or BNB Smart Chain via public RPC endpoints from non-browser processes
author: Security Arsenal Threat Intel
logsource:
category: network_connection
product: windows
detection:
selection_dest:
DestinationHostname|contains:
- '1rpc.io'
- 'api.pocket.network'
- 'rpc.sepolia'
- 'bsc-dataseed'
- 'eth-sepolia'
selection_proc:
Image|endswith:
- '\powershell.exe'
- '\node.exe'
- '\rundll32.exe'
- '\wscript.exe'
- '\mshta.exe'
condition: selection_dest and selection_proc
falsepositives:
- Legitimate Web3 development workstations (tune by host group)
level: medium
tags:
- attack.t1071.001
- attack.t1102.002
---
title: Shai-Hulud / ChainDrop Credential Harvesting from npm Package
date: 2026/10/08
id: 7c1e4f8a-chaindrop-npm-0003
status: experimental
description: Detects suspicious child processes of npm/node accessing credential stores (AWS, SSH, kubeconfig, Vault, npm tokens) consistent with the TensorLake 0.5.144 ChainDrop compromise
author: Security Arsenal Threat Intel
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\node.exe'
- '\npm.cmd'
- '\npm.exe'
selection_child:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\curl.exe'
- '\certutil.exe'
selection_paths:
CommandLine|contains:
- '.aws\credentials'
- '.ssh\id_'
- '.kube\config'
- '.npmrc'
- 'gh\hosts.yml'
- '.vault-token'
condition: selection_parent and selection_child and selection_paths
falsepositives:
- Legitimate dev CLI tooling (rare as npm child processes)
level: critical
tags:
- attack.t1552.001
- attack.t1552.004
- attack.t1195.002
// FortiBleed + Stealer C2 + EtherHiding composite hunt - Microsoft Sentinel
let FortiBleedIPs = dynamic(["103.27.186.156","154.202.59.169","45.154.12.132","80.75.212.113","85.11.187.8","193.8.187.2","45.227.254.210","77.91.118.10"]);
let StealerC2 = dynamic(["leaguejazire.com","hugo-mapp.co","unguidedfreewill.co","ironphantomcore.top","stormvenomforge.top","voidravenstorm.top","shadowemberstrike.top","oceanvw.click","citywebntw.com"]);
let RPCEndpoints = dynamic(["1rpc.io","eth-sepolia-testnet.api.pocket.network"]);
let lookback = 30d;
let NetHits = DeviceNetworkEvents
| where TimeGenerated > ago(lookback)
| where RemoteIP in~ (FortiBleedIPs)
or RemoteUrl has_any (StealerC2)
or RemoteUrl has_any (RPCEndpoints)
| project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, RemoteIP, RemoteUrl, RemotePort
| extend Hunt = case(
RemoteIP in~ (FortiBleedIPs), "FortiBleed harvesting infra",
RemoteUrl has_any (RPCEndpoints), "EtherHiding RPC lookup",
"Stealer C2");
let ProcHits = DeviceProcessEvents
| where TimeGenerated > ago(lookback)
| where (InitiatingProcessFileName =~ "explorer.exe" and FileName in~ ("powershell.exe","rundll32.exe","mshta.exe"))
or (ProcessCommandLine has_any ("DownloadString","IEX","WebClient") and InitiatingProcessFileName in~ ("chrome.exe","msedge.exe","firefox.exe","explorer.exe"))
or (FileName =~ "node.exe" and ProcessCommandLine has_any (".aws/credentials",".ssh/id_",".kube/config",".npmrc",".vault-token"))
| project TimeGenerated, DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName, SHA256
| extend Hunt = "ClickFix execution / ChainDrop credential access";
union NetHits, ProcHits
| summarize FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated), Artifacts=make_set(pack("proc", tostring(InitiatingProcessFileName), "cmd", tostring(InitiatingProcessCommandLine), "ip", tostring(RemoteIP), "url", tostring(RemoteUrl))) by DeviceName, Hunt
| order by LastSeen desc;
# Security Arsenal - Credential-Theft Campaign IOC Hunt (ClearFake / PhantomPolia / FortiBleed / ChainDrop)
# Run as administrator on endpoints; review output before remediation.
$ErrorActionPreference = 'SilentlyContinue'
Write-Host "=== [1/5] Network connections to FortiBleed harvesting infra ===" -ForegroundColor Cyan
$badIPs = @('103.27.186.156','154.202.59.169','45.154.12.132','80.75.212.113','85.11.187.8','193.8.187.2','45.227.254.210','77.91.118.10')
Get-NetTCPConnection | Where-Object { $badIPs -contains $_.RemoteAddress } |
Select-Object LocalAddress,LocalPort,RemoteAddress,RemotePort,State,OwningProcess,
@{n='Process';e={(Get-Process -Id $_.OwningProcess).ProcessName}} | Format-Table -AutoSize
Write-Host "=== [2/5] DNS cache for stealer C2 / EtherHiding RPC domains ===" -ForegroundColor Cyan
$c2Patterns = 'leaguejazire|hugo-mapp|unguidedfreewill|ironphantomcore|stormvenomforge|voidravenstorm|shadowemberstrike|oceanvw\.click|citywebntw|1rpc\.io|pocket\.network'
Get-DnsClientCache | Where-Object { $_.Entry -match $c2Patterns } | Format-Table Entry,Data,TimeToLive -AutoSize
Write-Host "=== [3/5] NetSupport Manager persistence (ClearFake RAT component) ===" -ForegroundColor Cyan
Get-ItemProperty 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run','HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' |
ForEach-Object { $_.PSObject.Properties } | Where-Object { $_.Value -match 'netsupport|client32|pf\.ch' } |
Format-Table Name,Value -AutoSize
Get-ChildItem 'C:\Program Files\NetSupport','C:\Program Files (x86)\NetSupport','$env:APPDATA' -Recurse -Filter 'client32.exe' |
Select-Object FullName,CreationTime | Format-Table -AutoSize
Write-Host "=== [4/5] TensorLake 0.5.144 (ChainDrop/Shai-Hulud) in node_modules and lockfiles ===" -ForegroundColor Cyan
$devPaths = @("$env:USERPROFILE\source","$env:USERPROFILE\repos","$env:USERPROFILE\projects","C:\dev")
foreach ($p in $devPaths) {
if (Test-Path $p) {
Get-ChildItem $p -Recurse -Filter 'package-lock.json' -Depth 4 |
Select-String -Pattern '"tensorlake".*0\.5\.144' -List |
Select-Object Path,LineNumber | Format-Table -AutoSize
}
}
$badHashes = @('25a0735d0db7dc40e5d45ce42d9c106067e6a66e184d967cfecfab17c3bcb5ef','b50a00900399ba99fb6ce1fc151519cb99d44320ef2a631f2237e1aea0ad6fec')
Get-ChildItem "$env:USERPROFILE" -Recurse -Filter 'tensorlake*' -Depth 6 | ForEach-Object {
if ($badHashes -contains (Get-FileHash $_.FullName -Algorithm SHA256).Hash.ToLower()) {
Write-Host "[!] MALICIOUS PACKAGE FILE: $($_.FullName)" -ForegroundColor Red } }
Write-Host "=== [5/5] ClickFix execution artifacts (RunMRU / suspicious PS history) ===" -ForegroundColor Cyan
Get-ItemProperty 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU' |
ForEach-Object { $_.PSObject.Properties } |
Where-Object { $_.Value -match 'powershell|mshta|rundll32|\\\\' } | Format-Table Name,Value -AutoSize
Get-Content "$env:APPDATA\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt" |
Select-String -Pattern 'IEX|DownloadString|WebClient|sepolia|1rpc' | Select-Object -First 20
Write-Host "=== Hunt complete. Any hits require credential rotation per IR runbook. ===" -ForegroundColor Green
Response Priorities
Immediate (0-4 hours):
- Block all FortiBleed IPv4s at the perimeter and retro-hunt VPN/firewall auth logs for successful logins from those IPs — any hit means compromised credentials and a potentially hostile active session.
- Push the TensorLake and malicious Firefox extension SHA-256 hashes to EDR blocklists; sinkhole the ClearFake/PhantomPolia C2 domains (
*.hugo-mapp.co,*.unguidedfreewill.co, the four PhantomPolia.topdomains,leaguejazire.com,oceanvw.click,citywebntw.com). - Run the PowerShell hunt across endpoints with recent browser-driven PowerShell alerts; check RunMRU and PSReadLine history for ClickFix paste-execution artifacts.
- Alert (do not block) on non-browser processes querying Sepolia/BSC RPC endpoints — this is the highest-fidelity EtherHiding signal available.
24 hours:
- Every pulse in this set involves credential theft — treat identity as compromised by default on any host with a detection hit. Force resets of browser-stored credentials, session token revocation (especially Microsoft 365/Google workspace refresh tokens), and crypto wallet key migration for affected users.
- If
tensorlake@0.5.144is found in any environment: rotate all developer secrets — npm tokens, GitHub PATs, AWS keys, Vault tokens, kubeconfigs, SSH keys — and audit downstream packages for Shai-Hulud self-propagation using the stolen tokens. - Inventory internet-facing FortiGate/SSL VPN appliances; verify firmware version, disable legacy SHA-256 password storage, enforce MFA, and force credential resets for all VPN accounts given offline-cracking risk.
- Audit installed Firefox extensions against the 16-extension blocklist; check for "Raabby WaIIet" homoglyph variants.
1 week:
- Harden ClickFix exposure: deploy browser isolation for uncategorized sites, use AppLocker/WDAC to prevent user-context
powershell.exe/mshta.exespawning from browsers and Explorer, and disable WebDAV client service where not required. - Lock down npm supply chain: enforce lockfile integrity checks in CI, pin registry to an internal proxy (Artifactory/Nexus) with quarantine scanning, require
--ignore-scriptsfor non-build installs, and scope npm tokens with expiration. - Move FortiGate admin interfaces off the public internet entirely (management VRF/jump host), and migrate all SSL VPN auth to SAML/OIDC with phishing-resistant MFA — FortiBleed demonstrates password-only VPN is now a harvested commodity at 86K-device scale.
- Add Sepolia/BSC JSON-RPC egress monitoring as a permanent detection, not a campaign-specific one — EtherHiding is now used by at least two independent operations.
Related Resources
Security Arsenal Incident Response Managed SOC & MDR Services AlertMonitor Threat Detection From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.