Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Vanta Stealer Drains Browser, Crypto, and Gaming Accounts
August 6, 2026
Critical Flaws in Anthropic, Google, OpenAI Coding Agents Allow RCE
August 6, 2026
Best Intrusion Detection & Prevention (IDS/IPS) Tools for 2026
August 6, 2026
Home/Threats/GHOSTYNETWORKS, OMEGATECH Host Malware Infrastructure for JS Skimmer Attacks
Threats

GHOSTYNETWORKS, OMEGATECH Host Malware Infrastructure for JS Skimmer Attacks

Key Takeaways A widespread malicious spam campaign, active since mid-2025, intensified in March and April 2026, targeting critical sectors globally. The attacks leverage a sophisticated JavaScript...

Sarah simpson
Sarah simpson
May 28, 2026 4 Min Read
60 0

Key Takeaways

  • A widespread malicious spam campaign, active since mid-2025, intensified in March and April 2026, targeting critical sectors globally.
  • The attacks leverage a sophisticated JavaScript backdoor and rely on “bulletproof” hosting infrastructure provided by GHOSTYNETWORKS (AS205759) and OMEGATECH (AS202412).
  • Targets include energy, automotive, and government finance entities across Ukraine, Russia, Poland, Germany, and Transnistria.
  • The primary motivation behind these attacks is financial gain, aligning with a significant increase in business email compromise losses.

Cybersecurity researchers have uncovered a sophisticated and persistent malicious spam campaign that has been active since mid-2025, escalating significantly in the first half of 2026. This operation, designed to distribute a highly obfuscated JavaScript backdoor, has targeted a diverse range of critical industries, including energy, automotive, and government finance sectors across multiple countries.

Table Of Content

  • Key Takeaways
  • The JavaScript Backdoor: Stealth and Persistence
  • Infrastructure of Abuse: GHOSTYNETWORKS and OMEGATECH
  • GHOSTYNETWORKS (AS205759)
  • OMEGATECH (AS202412)
  • What You Should Do
  • Indicators of Compromise (IoCs):-

The campaign, which saw a major surge in March 2026 and expanded further in April, demonstrated a deliberate focus on financially sensitive organizations. Notable victims include a prominent Ukrainian fast-moving consumer goods (FMCG) holding, a Russian oil-refining enterprise, automotive groups in Poland and Germany, and the Ministry of Finance of Transnistria. This consistent targeting underscores a clear financial motive, echoing the FBI’s report of over $3 billion in business email compromise losses in 2025 alone.

According to a report by Intrinsec researchers, their Cyber Threat Intelligence (CTI) team meticulously tracked these campaigns, ultimately exposing the resilient “bulletproof” hosting infrastructure that underpins them. Their investigation pinpointed two key autonomous systems, GHOSTYNETWORKS and OMEGATECH, as central to routing both the spam-sending IP addresses and the command-and-control (C2) servers for the malware.

The JavaScript Backdoor: Stealth and Persistence

The JavaScript backdoor itself is engineered for stealth and persistence. It is delivered to victims as a file nested within ZIP or RAR archives attached to malicious phishing emails. Upon execution, the malware gathers system information and transmits it to its C2 server using non-standard ports (e.g., 2002, 2004, 7273). This tactic, combined with an outdated Internet Explorer user-agent string, allows the malicious traffic to mimic ordinary browser activity, making detection more challenging for conventional security tools. Each infected machine is assigned a unique identifier, enabling the backdoor to maintain persistent communication with its operators.

Infrastructure of Abuse: GHOSTYNETWORKS and OMEGATECH

The resilience and longevity of these campaigns are largely attributable to the “bulletproof” hosting providers utilized by the threat actors. These providers are known for their lax policies regarding illicit content and their ability to quickly shift infrastructure to evade takedowns.

GHOSTYNETWORKS (AS205759)

GHOSTYNETWORKS, registered in Kentucky in January 2026, operates as AS205759 and was found to host one of the spam-sending IP addresses. Spamhaus, a leading authority on spam and cybercrime, has flagged four of its six announced network prefixes as abusive, describing the network as a facilitator of cybercrime globally. Intrinsec’s analysis confidently linked GHOSTYNETWORKS to OPTIBOUNCE, a now-defunct network also registered in Kentucky and previously associated with AnonRDP, another notorious bulletproof hosting provider. The common thread among multiple Kentucky-registered companies flagged for abusive content is the organizer name, Daniel Mishayev. During March 2026 alone, honeypots recorded over 30,000 network hits originating from IPs announced by GHOSTYNETWORKS.

OMEGATECH (AS202412)

The second critical component of the malicious infrastructure is OMEGATECH (AS202412), based in the Seychelles. This autonomous system hosted both the JavaScript backdoor’s C2 domain and an additional spam-sending domain. Spamhaus identifies OMEGATECH as a front for Virtualine, a Russia-based bulletproof provider frequently advertised on underground criminal forums. The sheer volume of malicious activity linked to OMEGATECH is striking, with honeypots logging more than 642,000 network hits from its IP addresses during March 2026, demonstrating its extensive use for cybercriminal operations.

What You Should Do

  • Block Malicious File Types: Configure email security gateways to block JavaScript-related attachments such as .js, .jse, and .mjs files. Additionally, block common archive formats like ZIP, ISO, and RAR if they are not routinely used for legitimate business purposes, as they often contain embedded malicious scripts.
  • Implement Application Controls: Enforce strict application controls to prevent the execution of scripting engines like wscript and cscript from untrusted paths. This significantly limits the attack surface for JavaScript-based backdoors.
  • Deploy Advanced Email Security: Utilize advanced email security solutions capable of detecting and filtering sophisticated phishing emails that carry malicious attachments and obfuscated content.
  • Block Known Abusive ASNs: Update firewall rules to block network prefixes associated with known bulletproof hosting providers like GHOSTYNETWORKS (AS205759) and OMEGATECH (AS202412) at the perimeter.
  • Conduct Employee Training: Regularly conduct cybersecurity awareness training and simulated phishing exercises to educate employees on how to identify and report suspicious emails and attachments. Human vigilance remains a crucial defense layer.
  • Monitor Network Traffic: Implement robust network monitoring to detect unusual outbound connections, especially those on non-standard ports (e.g., 2002, 2004, 7273) or those using suspicious user-agent strings (e.g., outdated Internet Explorer agents).

Indicators of Compromise (IoCs):-

Type Indicator Description
ASN 205759 GHOSTYNETWORKS
ASN 202412 OMEGATECH-AS
IPv4 83.142.209[.]64 Emits spam
IPv4 91.92.243[.]79 Emits spam and JS backdoor C2
IPv4 158.94.211[.]76 JS backdoor C2
Domain mail.talruit[.]com Emits spam
Domain talruit[.]com Emits spam
Domain scan.aryamint[.]com JS backdoor C2
Domain aryamint[.]com JS backdoor C2
Domain mpwirerope[.]com Emits spam
Domain ethara[.]org Linked to threat actor’s infrastructure
SHA-256 794fab796e48f97e976d99157913ab5beee5ae8ef2731bf2af2222ae5b6a1c65 JS backdoor – “QUOTE_B0426.js”
SHA-256 ac842e4adb445a76aad135828d56116858a1b7d37b4a103f493e175816df9bb2 JS backdoor – “PO 03603.zip”
SHA-256 33713a3650a3c1d64045c3832835dcacef92ad4f09c030fbe674454266880fea JS backdoor – “PO 26683.js”
SHA-256 7277f4dfb26a53f8ee47cac051a82f6709e07b6603f26ff3987cc64a137e07dc JS backdoor – “PO8767.rar”
SHA-256 232a179daf4db527c062b609ebb5f19310eea8f5c80afce6f763f5841110aed8 JS backdoor – “PO8767.js”

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwarephishingSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical Akamai CVE-2024-20780 Lets Attackers Bypass DNS Filtering

Next Post

Carnival Cruise Data Breach Exposes Millions of Customers’ Personal Information

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Fake Movie Download Exposes Passwords, Payments, Crypto Assets
August 6, 2026
Critical Oracle Solaris CVE-2024-21013 Flaw Lets Attackers Remotely Control Servers
August 6, 2026
Canadian Man Pleads Guilty to Hacking US Cloud Storage Provider
August 6, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us