GHOSTYNETWORKS (AS205759) and OMEGATECH (AS202412) Bulletproof Hosting Power Obfuscated JavaScript Backdoor Spam Campaign Targeting Energy, Automotive, FMCG, and Government Finance Across Ukraine, Russia, Poland, Germany, and Transnistria

GHOSTYNETWORKS (AS205759) and OMEGATECH (AS202412) (TL-2026-0617), also tracked as GHOSTYNETWORKS JS Backdoor Campaign, is a high-severity malware campaign, first published 2026-05-28. It has no confirmed attribution, affects Microsoft Windows Script Host (wscript.exe / cscript.exe), maps to 25 MITRE ATT&CK techniques (T1016, T1027, T1027.002), and is covered by 9 detection rules and 29 indicators of compromise.

Key facts for TL-2026-0617

Threat ID
TL-2026-0617
Also known as
GHOSTYNETWORKS JS Backdoor Campaign, OMEGATECH Spam Wave, Intrinsec JS-Coded Backdoor Campaign 2026
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-05-28
Last reviewed
2026-05-28
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
energy, oil-and-gas, automotive, fmcg, government, finance, manufacturing
Target regions
Ukraine, Russia, Poland, Germany, Transnistria, Eastern Europe, Central Europe
Detection rules
9
Indicators of compromise
29

Malware and tooling in GHOSTYNETWORKS (AS205759) and OMEGATECH (AS202412)

Malware and tooling: Intrinsec JS-Coded Backdoor (unnamed), AnonRDP, OPTIBOUNCE, Virtualine

Intrinsec CTI exposed a financially motivated, multi-wave malicious-spam campaign distributing a heavily obfuscated JavaScript backdoor via ZIP/RAR/ISO archive attachments. Adversaries route both the spam-sending infrastructure and the C2 channel through two recently provisioned bulletproof autonomous systems: GHOSTYNETWORKS (AS205759, Kentucky-registered Jan 2026, attributed to organizer Daniel Mishayev and historically linked to OPTIBOUNCE/AnonRDP) and OMEGATECH (AS202412, Seychelles, identified by Spamhaus as a front for the Russia-based Virtualine bulletproof provider). The JS implant beacons over non-standard ports (2002, 2004, 7273) using a forged legacy Internet Explorer user-agent, fingerprints victims with a unique identifier, and exfiltrates system metadata; March and April 2026 waves struck a major Ukrainian FMCG holding, a Russian oil-refining enterprise, automotive groups in Poland and Germany, and the Ministry of Finance of Transnistria.

How GHOSTYNETWORKS (AS205759) and OMEGATECH (AS202412) works

Intrinsec's CTI team tracked a sustained, financially motivated spam-borne backdoor operation whose infrastructure footprint traces to mid-2025 and which surged into major distribution waves during March and April 2026. The adversaries deliberately segregated their malicious estate into two bulletproof autonomous systems — GHOSTYNETWORKS (AS205759) and OMEGATECH (AS202412) — using one to host spam-sending mail infrastructure and a second to host the JavaScript backdoor's command-and-control domain and a secondary spam-sending domain, providing the operators with operational resilience and a measure of hosting-takedown resistance.

GHOSTYNETWORKS LLC, originated as AS205759 and registered in Kentucky in January 2026, currently announces six IPv4 prefixes including 36.255.97.0/24, 43.228.157.0/24, 46.151.182.0/24, 64.89.160.0/24, 64.89.161.0/24, and 83.142.209.0/24. Intrinsec attributes GHOSTYNETWORKS with high confidence to a now-defunct Kentucky-registered network named OPTIBOUNCE that was previously tied to the long-documented bulletproof RDP provider AnonRDP. The same organizing principal, Daniel Mishayev, appears across multiple Kentucky-registered shell companies, each routinely flagged by spam-blocklist operators for abusive content. OMEGATECH (AS202412), nominally headquartered in the Seychelles, hosts the JS backdoor's C2 domain alongside a second spam-sending domain; Spamhaus assesses OMEGATECH as a rebrand or front for Virtualine, a Russia-based bulletproof hosting provider openly advertised on Russian-language underground criminal forums.

Delivery is mass phishing. Victims receive emails carrying ZIP, RAR, or ISO archives whose interiors contain a heavily obfuscated JavaScript stage (.js, .jse, or .mjs). When a user double-clicks the script and Windows Script Host (wscript.exe) interprets it, the deobfuscated stage fingerprints the host (hostname, username, OS version, network configuration), assigns the infection a unique per-machine identifier so the handler can deduplicate and steer victims, and opens an outbound HTTP-like channel to the C2. The implant deliberately speaks on non-standard TCP destination ports — 2002, 2004, and 7273 — that are unlikely to appear in routine endpoint network telemetry, and it masquerades its outbound requests by sending a legacy Internet Explorer user-agent string that imitates the residual long-tail of legitimate browser traffic. The combination of archived script delivery, non-standard ports, and forged user-agent is designed to evade default secure-email-gateway controls, network proxies, and out-of-the-box EDR network heuristics.

Targeting is unambiguously financially motivated and cross-sectoral. Confirmed victims include a major Ukrainian fast-moving-consumer-goods holding, a Russian oil-refining enterprise, automotive industrial groups in Poland and Germany, and the Ministry of Finance of the unrecognized breakaway state of Transnistria. The April 2026 follow-on wave broadened the target set to additional financially sensitive institutions consistent with business-email-compromise (BEC) staging. FBI's IC3 has reported BEC losses exceeding $3 billion in 2025, and Intrinsec's targeting profile aligns with the staging phase of a BEC or finance-fraud operation rather than espionage; targeting of energy and government finance entities nonetheless raises significant escalation risk.

Mitigation guidance from Intrinsec includes hardening secure-email gateways to block .js, .jse, and .mjs attachments and any ZIP, ISO, or RAR archives containing executable scripts; deploying network telemetry rules that flag outbound TCP traffic to uncommon destination ports such as 2002/2004/7273; reviewing endpoint policy to disable Windows Script Host where business-justifiable; and pairing technical controls with regular employee phishing-awareness simulations. Defenders should also block or alert on all six GHOSTYNETWORKS prefixes and the major OMEGATECH prefix ranges at perimeter and DNS-level controls until the campaign infrastructure is fully retired.

MITRE ATT&CK techniques used in TL-2026-0617

Discovery

T1016 System Network Configuration Discovery; T1033 System Owner/User Discovery; T1082 System Information Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1027.002 Obfuscated Files or Information: Software Packing; T1036 Masquerading; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059 Command and Scripting Interpreter; T1059.007 Command and Scripting Interpreter: JavaScript; T1204.002 User Execution: Malicious File

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1105 Ingress Tool Transfer; T1132.001 Data Encoding: Standard Encoding; T1571 Non-Standard Port

Initial Access

T1566 Phishing; T1566.001 Phishing: Spearphishing Attachment

Resource Development

T1583 Acquire Infrastructure; T1583.001 Acquire Infrastructure: Domains; T1583.004 Acquire Infrastructure: Server; T1583.005 Acquire Infrastructure: Botnet; T1585 Establish Accounts; T1587.001 Develop Capabilities: Malware; T1608.001 Stage Capabilities: Upload Malware

Affected products and versions in GHOSTYNETWORKS (AS205759) and OMEGATECH (AS202412)

  • Microsoft — Windows Script Host (wscript.exe / cscript.exe)
    Vulnerable versions: all supported Windows desktop and server SKUs with WSH enabled
  • Microsoft — Windows Explorer / Archive handling
    Vulnerable versions: 10; 11; Server 2016+
  • Generic — Email clients consuming ZIP/RAR/ISO attachments
    Vulnerable versions: any client that permits user execution of attached script files

Remediation for GHOSTYNETWORKS (AS205759) and OMEGATECH (AS202412)

Immediate actions

  • Block .js, .jse, and .mjs attachments and embedded scripts at secure email gateway
  • Block or strip ZIP, RAR, and ISO archives containing executable script content at email gateway
  • Sinkhole or null-route GHOSTYNETWORKS AS205759 prefixes (36.255.97.0/24, 43.228.157.0/24, 46.151.182.0/24, 64.89.160.0/24, 64.89.161.0/24, 83.142.209.0/24) at perimeter
  • Block outbound TCP to non-business destination ports including 2002, 2004, and 7273 from user workstations
  • Alert on Windows Script Host (wscript.exe / cscript.exe) child processes spawned from Explorer.exe or from archive utilities (WinRAR, 7zip, Windows Explorer ZIP)

Workarounds

  • Open suspicious archive attachments only in isolated browser/VM sandboxes
  • Default-deny inbound emails with archive attachments from external senders for non-business roles
  • Re-image and rotate credentials on any host observed executing wscript.exe with a script extracted from an inbound email archive

Longer-term hardening

  • Disable or restrict Windows Script Host execution via Software Restriction Policies / WDAC where business-tolerable
  • Deploy EDR with behavioral detection for script interpreters making outbound network connections to non-standard ports
  • Implement DMARC/DKIM/SPF enforcement and external sender warning banners
  • Adopt egress filtering allowlist for high-risk endpoint populations (finance, executives, IT admins)
  • Maintain a continuously updated bulletproof-hosting ASN blocklist incorporating Spamhaus DROP/EDROP and ASN-level reputation feeds

Weaknesses (CWE) in GHOSTYNETWORKS (AS205759) and OMEGATECH (AS202412)

CWE-829, CWE-94, CWE-693

Timeline of GHOSTYNETWORKS (AS205759) and OMEGATECH (AS202412)

  • Intrinsec retrospective analysis traces the operator's spam and C2 infrastructure footprint to mid-2025, indicating long-running tradecraft predating dedicated bulletproof ASN registration.
  • GHOSTYNETWORKS LLC registers AS205759 in Kentucky; same organizing principal Daniel Mishayev links the network to defunct OPTIBOUNCE and historical AnonRDP bulletproof RDP service.
  • First major March 2026 spam wave delivers ZIP/RAR archives containing obfuscated JavaScript backdoor to Ukrainian FMCG holding, Russian oil-refining enterprise, Polish and German automotive groups, and the Ministry of Finance of Transnistria.
  • JavaScript implant observed beaconing to OMEGATECH (AS202412)-hosted C2 domains on TCP ports 2002, 2004, and 7273 using a forged legacy Internet Explorer user-agent string.
  • April 2026 follow-on wave broadens targeting to additional financially sensitive institutions consistent with business-email-compromise staging.
  • Spamhaus identifies OMEGATECH (AS202412, Seychelles) as a front for Russia-based bulletproof hosting provider Virtualine advertised on Russian-language criminal forums.
  • Cyber Security News publishes summary of Intrinsec CTI investigation; campaign attribution, infrastructure mapping, and mitigation guidance enter public threat-intelligence record.
  • As of 2026-05-29, this remains ACTIVE: both bulletproof ASNs are still announcing prefixes in BGP (AS202412 ~20 /24s, AS205759 6 /24s with traceroutes dated 2026-05-28) with no takedown, and Spamhaus/Breakglass confirm OMEGATECH/Virtualine still hosting active malware C2. The WSH/archived-JS technique has no patch and disclosure is only days old.

Sources cited for GHOSTYNETWORKS (AS205759) and OMEGATECH (AS202412)

Threats related to GHOSTYNETWORKS (AS205759) and OMEGATECH (AS202412)

Detection coverage for TL-2026-0617

As of 2026-05-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0617 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats