Carrier-Themed Malware Campaign Targeting Logistics and Trucking

The Freight-Intel Network & Defense (FIND) Threat Research team recently discovered a coordinated cyber campaign targeting logistics and trucking businesses. By tracing connections between carrier-impersonation websites, malicious downloads and remote-access infrastructure, FIND identified hundreds of files, multiple delivery methods and a malware family we are naming GaloyanRAT.
Several indicators link the activity to Armenian-speaking cybercriminals, including an Armenian-language code comment and distinctive identifiers reused across the malware and delivery files. These findings indicate an Armenian-language development context.

This article explains what the campaign was trying to achieve, why it matters to freight businesses and how organisations can reduce their risk. An accompanying technical analysis provides the underlying malware, infrastructure, execution-chain and detection research for IT, cybersecurity and threat-intelligence specialists.
At Freight-Intel Network & Defense (FIND), we commonly link on-the-ground cargo thefts back to cyber incidents involving an impersonated carrier. A fraudulent pickup or missing load may begin with a stolen login, a compromised device or a carrier identity taken over online. Criminals can then use that trusted identity on a load board or similar platform to book and divert freight.
What was the campaign trying to achieve?
The first goal was access. The campaign used carrier-themed websites and files disguised as everyday freight paperwork to persuade recipients to open malicious content.
Once inside, the tools could give criminals ongoing remote access, steal passwords and active browser sessions, view files and screens, collect payment information and install further software. Some routes silently installed commercial remote-support tools, helping the activity blend in with legitimate IT administration.
For a logistics business, that access could expose active loads, pickup and delivery details, cargo values, driver information, carrier packets, insurance documents and payment conversations. Criminals could use this information to:
impersonate a carrier, broker, dispatcher or driver;
book a load using a stolen carrier identity;
change pickup or delivery instructions;
divert freight to a criminal-controlled location;
support fraudulent onboarding or double brokering; or
redirect payments and reuse stolen documents in later fraud.
The collection also included a tool for cryptocurrency mining. This suggests that infected systems could be used for more than one purpose, but remote access and information theft were the most important risks for logistics organisations.
Why logistics information is valuable
An attacker does not need access to an entire transport-management system to cause harm. One compromised dispatcher, broker or carrier account may reveal:
active and upcoming loads;
pickup and delivery addresses;
appointment times and reference numbers;
cargo descriptions and values;
driver and vehicle details;
carrier packets and insurance documents;
rate confirmations and proof-of-delivery files;
customer and supplier contact details; and
payment instructions and banking conversations.
That information can make fraud far more convincing. A criminal may be able to enter an existing conversation, pose as a known carrier or broker, submit stolen documents, change contact details or give a driver new instructions that appear genuine.
In many cargo-theft schemes, criminals first compromise or steal a legitimate carrier identity. They then use that identity on a load board or similar freight platform to book a load as the trusted carrier. Once the booking is accepted, the pickup or delivery instructions can be changed and the freight diverted to a location controlled by the criminals. Because the account, documents and company details appear legitimate, the fraud may not be discovered until the expected carrier or consignee reports that the load never arrived.
A sustained and adaptable operation
Seven websites were directly linked to the campaign, with six more assessed as closely related. Domains such as carrier-contracts[.]com, carrier-files[.]com, carrierenrollupdate[.]com and carrierreadydocs[.]com were designed to sound normal within the industry.
![Figure X - carrierenrollupdate[.]com malware delivery site](https://static.wixstatic.com/media/734438_c5ca4be8b6d64d3fb734bd6e8d216539~mv2.png/v1/fill/w_980,h_420,al_c,q_90,usm_0.66_1.00_0.01,enc_avif,quality_auto/734438_c5ca4be8b6d64d3fb734bd6e8d216539~mv2.png)
FIND used the Have I Been Squatted (HIBS) platform to expand from confirmed domains and identify similar registrations. Potential matches were then compared using registration details, nameservers, website content, tracking code and links to campaign payloads. This helped uncover additional infrastructure while filtering out unrelated websites that happened to use similar freight-related names.
The operators also used several delivery methods, cloud-hosted downloads, fake verification pages and different remote-access tools. Some routes created more than one way back into the same device. This made the campaign harder to disrupt and allowed it to continue if one website or tool stopped working.
How to spot it
Warning signs include:
a carrier or broker link that does not use the organisation’s normal domain;
an urgent request about onboarding, compliance, payment or a rate confirmation;
a known company’s branding displayed on an unrelated website;
a download sent before a new business relationship has been verified;
a supposed document ending in .vbs, .wsf, .bat, .cmd, .ps1, .js, .msi, .exe or .vhdx;
a filename with two endings, such as Carrier_Packet.pdf.vbs;
a website asking the user to open a system tool or paste a command.
Reducing the risk
No single product will stop every campaign. Effective protection should include:
A good managed SOC. Security specialists should monitor warnings, investigate suspicious activity and provide a clear route to containment, including outside normal office hours.
EDR and ITDR. Endpoint protection can identify harmful activity on devices, while identity monitoring can detect unusual logins, stolen sessions and misuse of employee or cloud accounts.
Domain and download controls. Block file types that are not required for normal freight workflows.
Infostealer, domain and brand monitoring. Watch for company accounts appearing in infostealer logs or known breach data. Monitor lookalike domains, fake websites, copied branding and fraudulent carrier identities on load boards and freight platforms.
Security awareness training. Use examples employees actually encounter, including carrier packets, rate confirmations and proof-of-delivery requests. Make reporting quick and blame-free.
Incident-response planning. Establish who will isolate an affected device, cancel stolen sessions, contact insurers and partners, review active loads and check for changed delivery or payment instructions.
How FIND can help
FIND works with logistics companies, trucking firms, freight brokers, carriers and insurance partners seeking stronger monitoring across devices and identities, better preparation and practical support when suspicious activity occurs.
If your organisation would like further information about managed SOC solutions or strengthening its security coverage, email us at find@freight-intel.com.
Comments