GHOSTYNETWORKS, OMEGATECH Host Malware Infrastructure for JS Skimmer Attacks
Key Takeaways A widespread malicious spam campaign, active since mid-2025, intensified in March and April 2026, targeting critical sectors globally. The attacks leverage a sophisticated JavaScript...
Key Takeaways
- A widespread malicious spam campaign, active since mid-2025, intensified in March and April 2026, targeting critical sectors globally.
- The attacks leverage a sophisticated JavaScript backdoor and rely on “bulletproof” hosting infrastructure provided by GHOSTYNETWORKS (AS205759) and OMEGATECH (AS202412).
- Targets include energy, automotive, and government finance entities across Ukraine, Russia, Poland, Germany, and Transnistria.
- The primary motivation behind these attacks is financial gain, aligning with a significant increase in business email compromise losses.
Cybersecurity researchers have uncovered a sophisticated and persistent malicious spam campaign that has been active since mid-2025, escalating significantly in the first half of 2026. This operation, designed to distribute a highly obfuscated JavaScript backdoor, has targeted a diverse range of critical industries, including energy, automotive, and government finance sectors across multiple countries.
Table Of Content
The campaign, which saw a major surge in March 2026 and expanded further in April, demonstrated a deliberate focus on financially sensitive organizations. Notable victims include a prominent Ukrainian fast-moving consumer goods (FMCG) holding, a Russian oil-refining enterprise, automotive groups in Poland and Germany, and the Ministry of Finance of Transnistria. This consistent targeting underscores a clear financial motive, echoing the FBI’s report of over $3 billion in business email compromise losses in 2025 alone.
According to a report by Intrinsec researchers, their Cyber Threat Intelligence (CTI) team meticulously tracked these campaigns, ultimately exposing the resilient “bulletproof” hosting infrastructure that underpins them. Their investigation pinpointed two key autonomous systems, GHOSTYNETWORKS and OMEGATECH, as central to routing both the spam-sending IP addresses and the command-and-control (C2) servers for the malware.
The JavaScript Backdoor: Stealth and Persistence
The JavaScript backdoor itself is engineered for stealth and persistence. It is delivered to victims as a file nested within ZIP or RAR archives attached to malicious phishing emails. Upon execution, the malware gathers system information and transmits it to its C2 server using non-standard ports (e.g., 2002, 2004, 7273). This tactic, combined with an outdated Internet Explorer user-agent string, allows the malicious traffic to mimic ordinary browser activity, making detection more challenging for conventional security tools. Each infected machine is assigned a unique identifier, enabling the backdoor to maintain persistent communication with its operators.
Infrastructure of Abuse: GHOSTYNETWORKS and OMEGATECH
The resilience and longevity of these campaigns are largely attributable to the “bulletproof” hosting providers utilized by the threat actors. These providers are known for their lax policies regarding illicit content and their ability to quickly shift infrastructure to evade takedowns.
GHOSTYNETWORKS (AS205759)
GHOSTYNETWORKS, registered in Kentucky in January 2026, operates as AS205759 and was found to host one of the spam-sending IP addresses. Spamhaus, a leading authority on spam and cybercrime, has flagged four of its six announced network prefixes as abusive, describing the network as a facilitator of cybercrime globally. Intrinsec’s analysis confidently linked GHOSTYNETWORKS to OPTIBOUNCE, a now-defunct network also registered in Kentucky and previously associated with AnonRDP, another notorious bulletproof hosting provider. The common thread among multiple Kentucky-registered companies flagged for abusive content is the organizer name, Daniel Mishayev. During March 2026 alone, honeypots recorded over 30,000 network hits originating from IPs announced by GHOSTYNETWORKS.
OMEGATECH (AS202412)
The second critical component of the malicious infrastructure is OMEGATECH (AS202412), based in the Seychelles. This autonomous system hosted both the JavaScript backdoor’s C2 domain and an additional spam-sending domain. Spamhaus identifies OMEGATECH as a front for Virtualine, a Russia-based bulletproof provider frequently advertised on underground criminal forums. The sheer volume of malicious activity linked to OMEGATECH is striking, with honeypots logging more than 642,000 network hits from its IP addresses during March 2026, demonstrating its extensive use for cybercriminal operations.
What You Should Do
- Block Malicious File Types: Configure email security gateways to block JavaScript-related attachments such as .js, .jse, and .mjs files. Additionally, block common archive formats like ZIP, ISO, and RAR if they are not routinely used for legitimate business purposes, as they often contain embedded malicious scripts.
- Implement Application Controls: Enforce strict application controls to prevent the execution of scripting engines like
wscriptandcscriptfrom untrusted paths. This significantly limits the attack surface for JavaScript-based backdoors. - Deploy Advanced Email Security: Utilize advanced email security solutions capable of detecting and filtering sophisticated phishing emails that carry malicious attachments and obfuscated content.
- Block Known Abusive ASNs: Update firewall rules to block network prefixes associated with known bulletproof hosting providers like GHOSTYNETWORKS (AS205759) and OMEGATECH (AS202412) at the perimeter.
- Conduct Employee Training: Regularly conduct cybersecurity awareness training and simulated phishing exercises to educate employees on how to identify and report suspicious emails and attachments. Human vigilance remains a crucial defense layer.
- Monitor Network Traffic: Implement robust network monitoring to detect unusual outbound connections, especially those on non-standard ports (e.g., 2002, 2004, 7273) or those using suspicious user-agent strings (e.g., outdated Internet Explorer agents).
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| ASN | 205759 | GHOSTYNETWORKS |
| ASN | 202412 | OMEGATECH-AS |
| IPv4 | 83.142.209[.]64 | Emits spam |
| IPv4 | 91.92.243[.]79 | Emits spam and JS backdoor C2 |
| IPv4 | 158.94.211[.]76 | JS backdoor C2 |
| Domain | mail.talruit[.]com | Emits spam |
| Domain | talruit[.]com | Emits spam |
| Domain | scan.aryamint[.]com | JS backdoor C2 |
| Domain | aryamint[.]com | JS backdoor C2 |
| Domain | mpwirerope[.]com | Emits spam |
| Domain | ethara[.]org | Linked to threat actor’s infrastructure |
| SHA-256 | 794fab796e48f97e976d99157913ab5beee5ae8ef2731bf2af2222ae5b6a1c65 | JS backdoor – “QUOTE_B0426.js” |
| SHA-256 | ac842e4adb445a76aad135828d56116858a1b7d37b4a103f493e175816df9bb2 | JS backdoor – “PO 03603.zip” |
| SHA-256 | 33713a3650a3c1d64045c3832835dcacef92ad4f09c030fbe674454266880fea | JS backdoor – “PO 26683.js” |
| SHA-256 | 7277f4dfb26a53f8ee47cac051a82f6709e07b6603f26ff3987cc64a137e07dc | JS backdoor – “PO8767.rar” |
| SHA-256 | 232a179daf4db527c062b609ebb5f19310eea8f5c80afce6f763f5841110aed8 | JS backdoor – “PO8767.js” |
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.