← Dispatches

TLP:CLEAR · 2026-07-29

Zerodark: Zero Reputation, Dark Payload

zerodark advertised free USA “COMPANY” crypto-investor leads with zero reputation on the board. The ZIP was a passworded WinRAR SFX that silently launched Millenium RAT v4.3. We decrypted the Telegram C2 and delivered an operator notice into two live channels.

Forum bait post by zerodark advertising free USA COMPANY crypto-investor leads (COMPANY name redacted)

We pulled a ZIP marketed as free USA crypto-investor leads for the company off a leak forum. The seller was zerodark — joined May 2026, seventy-eight posts, zero reputation. The thread title screamed leads. The body pasted a COMPANY smart-contract README like a GitHub dump. The archive was neither. It was a passworded WinRAR self-extractor that silently launched five Windows payloads, three of them Millenium RAT Builder v4.3. We reversed the configs, walked into the Telegram C2, and told the operators their channel was no longer theirs.

The Forum Lure

On 2026-07-16 at 19:53, zerodark posted FREE USA COMPANY CRYPTO INVESTORS LEADS in the leak section. Profile badges read Caller and Member. Credits sat at 780. Reputation sat at nothing. That combination — high post volume, no trust score — is how throwaway sellers look when they are farming downloads, not building a name.

The post sold two stories at once. The title promised investor PII. The body claimed a repository of the company’s Solidity contracts on EVM chains, Hardhat-managed, with the usual developer table of contents: setup, linting, testing, deployment, FiatToken features, pausable, upgradeable, blacklist, mint/burn. That README was cover. The download was the payload.

Opening the Archive

PropertyValue
Outer ZIP7258 USA COMPANY Crypto Investors Leads.zip
SHA-2561936d151d4004ddb2d2d4ed144acd047c75ee6937edefa54bb2579ad67096b52
Companion filePassword .txtpass 1212
Inner dropperWin64 WinRAR SFX EXE
SFX SHA-256bcdc0ada0a466ff5c137d7093452a86a5094661560f1895db283c94ccd5603d6
Embedded archiveRAR5, AES-encrypted, solid, password 1212

The SFX comment script does not ask permission:

Setup=clip.exe
Setup=crack.exe
Setup=installer.exe
Setup=registeration.exe
Setup=setup.exe
Silent=1
Overwrite=1

Run the “leads” EXE on Windows and all five binaries extract and launch with no UI. The encrypted RAR also packs a copied company fiat-token / Hardhat tree — dozens of .sol and .ts files — so anyone who digs past the EXEs sees “source” and feels smarter for it. That tree is padding. The business end is the silent Setup list.

Five Payloads, One Builder

FileRoleSHA-256
clip.exeClipboard stealer (valkyrie_payload.pdb); persists as WindowsHealthMonitor8098d0cf7a2460b14d7145b0c15a183c5fdbaa9e3932b1ee701aa4c2d59c0d9c
crack.exeFake NexaSoft / Nexa Update Manager Pro (.NET)3b35d3233e08d7c7a43a0bc0a899ce14cd6797949e96af0c6b3c32f690ab4815
installer.exeMillenium RAT — Telegram C2, browser / Discord / wallet theft94ffe61fb9619a00d8c1066dc8728df2af733f0b9ca8783a93ecbe1e52e59562
registeration.exeMillenium RAT — Defender cripple + secondary drops32e167e167c82f04b203c220b56edb95bbc3869254c7b792521a490c97e9507a
setup.exeMillenium RAT — Telegram C2748a02784c8a04459884778a66b2dbb5156b01b324c7b73f06c8058596d1a030

Path artifacts from the stubs land on Millenium RAT Builder V4.3 under builder user attat:

C:\Users\attat\source\repos\Millenium RAT Builder V4.3\Stub\

Stale GitHub staging under attatier/Cloud (MilInfo.txt, Mil2.txt) returned 404 at analysis time. The family identification does not depend on those URLs staying live.

Millenium parks config in PE RCDATA as UTF-16 Base64, pipe-padded for hash variance, then XOR’d. The archive password 1212 does not decrypt that config. The working XOR key from this build is:

fE5RNoV378Z2KsG6KG4CmTXf6v5lpKSW

Decrypting the C2

With the key in hand, the bots fell out of the binaries. C2 rides abused legitimate services — Telegram Bot API for command traffic, GoFile for secondary uploads, public IP geo lookups for enrichment. Those platforms are not the indicator. The bots are.

PayloadBotChat IDPersistence label
registeration.exe@mr14maybot-5150531439MsEdgeUpdate / svchost.exe masquerade
installer.exe@Billa2Bot_bot (Billabot)-5180660112vshost.exe masquerade
setup.exetoken later revoked8282123288MsEdgeUpdate / svchost.exe masquerade

registeration.exe init cripples Defender preferences at volume scope and dropruns further stages from actor infrastructure:

hxxp://thesnapchatmodapk[.]com/wdd.bat
hxxp://thesnapchatmodapk[.]com/mine.bat
hxxp://thesnapchatmodapk[.]com/update1.exe
hxxp://thesnapchatmodapk[.]com/update2.exe
hxxp://thesnapchatmodapk[.]com/update3.exe

setup.exe pointed at the same host’s update2.exe / update3.exe. Once resident, the RAT wants browser cookies and passwords, autofill and cards, clipboard, Telegram tdata, Discord tokens, extension wallets, screenshots, and desktop files.

We Walked Into the Channel

On 2026-07-29 we used the recovered tokens and transmitted the following notice into the operator chats:

ATTENTION OPERATOR

This channel is under Intercept Cell control.

Cipher Cortex — Intercept Cell unit has seized operational custody of this bot infrastructure. Your Telegram C2 endpoints, bot tokens, and associated chat sessions are now monitored, logged, and retained as evidence.

We have:
• Identified your Millenium RAT builds and staging chain
• Mapped your exfiltration paths and secondary drop hosts
• Correlated victim telemetry to this command channel
• Notified affected parties and escalated to partner response teams

Continued use of this infrastructure will be treated as active targeting of monitored victims. Every command, upload, and callback from this point forward is observed.

You are no longer invisible.
You are no longer unattributed.
You are no longer in control of this channel.

Stand down.
Delete residual access.
Do not attempt further contact with victims tied to this campaign.

Intercept Cell is watching.
Cipher Cortex is documenting.

— Intercept Cell / Cipher Cortex
ChannelDestinationResultEvidence
registeration.exe@mr14maybot-5150531439DeliveredHTTP 200, message_id 136695
installer.exe@Billa2Bot_bot-5180660112DeliveredHTTP 200, message_id 20522
setup.exetoken 8633556590:…8282123288FailedTelegram 400Logged out

Two of three channels accepted custody language in cleartext. One bot was already dead. The operators who still had sessions got the message the same way their victims’ machines would have — through the C2 they built.

The 7,258-Line Fiction

Buried in the RAR is a spreadsheet named like a jackpot: COMPANY.com - 7258 Line.xlsx (SHA-256 ef5adfc58fd3b699c6f1f9e2f4a2f6544cfb238f0e3d1e9c09c8082682b3bbce). The filename claims seven thousand rows. The sheet holds 108. Fields are ordinary USA contact columns — email, name, address, phone — with every source value pointed at the company’s public site. No wallets. No balances. No KYC. No transactions. It is bait formatting, not an investor book. We are not republishing the contact table.

Assessment

This is a leak-forum download farm wearing company branding. Zerodark’s zero-reputation profile, the dual lure (fake leads + fake Solidity tree), and the silent five-payload SFX are consistent with commodity Millenium distribution, not a targeted intrusion into the company itself. The company name is the hook. The product is stealer/RAT access.

We assess with high confidence that:

1. The distributed ZIP/SFX chain is malicious and matches Millenium RAT Builder v4.3 built by attat.

2. Telegram bots @mr14maybot and @Billa2Bot_bot were live C2 for this package on 2026-07-29, and both received our notice.

3. thesnapchatmodapk[.]com is actor staging for follow-on drops from this build.

4. The spreadsheet is decoy PII, not a genuine multi-thousand-row investor leak.

Defenders should refuse to execute the SFX, hunt the hashes and staging URLs below, report the named Telegram bots, and treat any host that ran the chain as fully compromised for browser and messenger secrets. Do not wholesale-block Telegram or GoFile — hunt the specific bots, tokens, and chat IDs.

IOC Summary

Archives

IndicatorTypeNotes
1936d151d4004ddb2d2d4ed144acd047c75ee6937edefa54bb2579ad67096b52SHA256Outer ZIP
bcdc0ada0a466ff5c137d7093452a86a5094661560f1895db283c94ccd5603d6SHA256WinRAR SFX EXE (password 1212)
ef5adfc58fd3b699c6f1f9e2f4a2f6544cfb238f0e3d1e9c09c8082682b3bbceSHA256Bait XLSX (108 rows)

Payloads

IndicatorTypeNotes
8098d0cf7a2460b14d7145b0c15a183c5fdbaa9e3932b1ee701aa4c2d59c0d9cSHA256clip.exe clipboard stealer
3b35d3233e08d7c7a43a0bc0a899ce14cd6797949e96af0c6b3c32f690ab4815SHA256crack.exe fake NexaSoft
94ffe61fb9619a00d8c1066dc8728df2af733f0b9ca8783a93ecbe1e52e59562SHA256installer.exe Millenium (@Billa2Bot_bot)
32e167e167c82f04b203c220b56edb95bbc3869254c7b792521a490c97e9507aSHA256registeration.exe Millenium (@mr14maybot)
748a02784c8a04459884778a66b2dbb5156b01b324c7b73f06c8058596d1a030SHA256setup.exe Millenium (token revoked)

Network / C2

IndicatorTypeNotes
thesnapchatmodapk[.]comDomainActor staging host
hxxp://thesnapchatmodapk[.]com/wdd.batURLSecondary drop
hxxp://thesnapchatmodapk[.]com/mine.batURLSecondary drop
hxxp://thesnapchatmodapk[.]com/update1.exeURLSecondary drop
hxxp://thesnapchatmodapk[.]com/update2.exeURLSecondary drop
hxxp://thesnapchatmodapk[.]com/update3.exeURLSecondary drop
@mr14maybotTelegram botLive C2; notice delivered
@Billa2Bot_botTelegram botLive C2; notice delivered
-5150531439Telegram chat ID@mr14maybot group
-5180660112Telegram chat IDBillabot group
8282123288Telegram chat IDsetup.exe channel (bot logged out)
8707453115:AAHcBGY-HkBvWdOgrgV0RrW3GeAyszNcFwQTelegram bot token@mr14maybot
8577105006:AAFIsVU-okV-VuC6iBL3hckQEAkVLfOFHywTelegram bot token@Billa2Bot_bot
8633556590:AAFPibTWDH-4E40BACytRmm88AnoXwwHnPkTelegram bot tokensetup.exe (revoked)

Host / Tradecraft

IndicatorTypeNotes
fE5RNoV378Z2KsG6KG4CmTXf6v5lpKSWXOR keyMillenium RCDATA decrypt (this build)
WindowsHealthMonitorRun-key / Startup nameclip.exe persistence label
hxxps://raw[.]githubusercontent[.]com/attatier/Cloud/main/MilInfo.txtURLBuilder staging (404 at analysis)
hxxps://raw[.]githubusercontent[.]com/attatier/Cloud/main/Mil2.txtURLBuilder staging (404 at analysis)
C:\Users\attat\source\repos\Millenium RAT Builder V4.3\Stub\Builder pathStub path artifact

*Company brand names in the lure are redacted as COMPANY; hashes identify the original samples.*

Intercept Cell Research is a Cipher Cortex research program. Hooked Scams is a scam investigation series from Intercept Cell Research.