
We pulled a ZIP marketed as free USA crypto-investor leads for the company off a leak forum. The seller was zerodark — joined May 2026, seventy-eight posts, zero reputation. The thread title screamed leads. The body pasted a COMPANY smart-contract README like a GitHub dump. The archive was neither. It was a passworded WinRAR self-extractor that silently launched five Windows payloads, three of them Millenium RAT Builder v4.3. We reversed the configs, walked into the Telegram C2, and told the operators their channel was no longer theirs.
The Forum Lure
On 2026-07-16 at 19:53, zerodark posted FREE USA COMPANY CRYPTO INVESTORS LEADS in the leak section. Profile badges read Caller and Member. Credits sat at 780. Reputation sat at nothing. That combination — high post volume, no trust score — is how throwaway sellers look when they are farming downloads, not building a name.
The post sold two stories at once. The title promised investor PII. The body claimed a repository of the company’s Solidity contracts on EVM chains, Hardhat-managed, with the usual developer table of contents: setup, linting, testing, deployment, FiatToken features, pausable, upgradeable, blacklist, mint/burn. That README was cover. The download was the payload.
Opening the Archive
| Property | Value |
|---|---|
| Outer ZIP | 7258 USA COMPANY Crypto Investors Leads.zip |
| SHA-256 | 1936d151d4004ddb2d2d4ed144acd047c75ee6937edefa54bb2579ad67096b52 |
| Companion file | Password .txt → pass 1212 |
| Inner dropper | Win64 WinRAR SFX EXE |
| SFX SHA-256 | bcdc0ada0a466ff5c137d7093452a86a5094661560f1895db283c94ccd5603d6 |
| Embedded archive | RAR5, AES-encrypted, solid, password 1212 |
The SFX comment script does not ask permission:
Setup=clip.exe
Setup=crack.exe
Setup=installer.exe
Setup=registeration.exe
Setup=setup.exe
Silent=1
Overwrite=1
Run the “leads” EXE on Windows and all five binaries extract and launch with no UI. The encrypted RAR also packs a copied company fiat-token / Hardhat tree — dozens of .sol and .ts files — so anyone who digs past the EXEs sees “source” and feels smarter for it. That tree is padding. The business end is the silent Setup list.
Five Payloads, One Builder
| File | Role | SHA-256 |
|---|---|---|
clip.exe | Clipboard stealer (valkyrie_payload.pdb); persists as WindowsHealthMonitor | 8098d0cf7a2460b14d7145b0c15a183c5fdbaa9e3932b1ee701aa4c2d59c0d9c |
crack.exe | Fake NexaSoft / Nexa Update Manager Pro (.NET) | 3b35d3233e08d7c7a43a0bc0a899ce14cd6797949e96af0c6b3c32f690ab4815 |
installer.exe | Millenium RAT — Telegram C2, browser / Discord / wallet theft | 94ffe61fb9619a00d8c1066dc8728df2af733f0b9ca8783a93ecbe1e52e59562 |
registeration.exe | Millenium RAT — Defender cripple + secondary drops | 32e167e167c82f04b203c220b56edb95bbc3869254c7b792521a490c97e9507a |
setup.exe | Millenium RAT — Telegram C2 | 748a02784c8a04459884778a66b2dbb5156b01b324c7b73f06c8058596d1a030 |
Path artifacts from the stubs land on Millenium RAT Builder V4.3 under builder user attat:
C:\Users\attat\source\repos\Millenium RAT Builder V4.3\Stub\
Stale GitHub staging under attatier/Cloud (MilInfo.txt, Mil2.txt) returned 404 at analysis time. The family identification does not depend on those URLs staying live.
Millenium parks config in PE RCDATA as UTF-16 Base64, pipe-padded for hash variance, then XOR’d. The archive password 1212 does not decrypt that config. The working XOR key from this build is:
fE5RNoV378Z2KsG6KG4CmTXf6v5lpKSW
Decrypting the C2
With the key in hand, the bots fell out of the binaries. C2 rides abused legitimate services — Telegram Bot API for command traffic, GoFile for secondary uploads, public IP geo lookups for enrichment. Those platforms are not the indicator. The bots are.
| Payload | Bot | Chat ID | Persistence label |
|---|---|---|---|
registeration.exe | @mr14maybot | -5150531439 | MsEdgeUpdate / svchost.exe masquerade |
installer.exe | @Billa2Bot_bot (Billabot) | -5180660112 | vshost.exe masquerade |
setup.exe | token later revoked | 8282123288 | MsEdgeUpdate / svchost.exe masquerade |
registeration.exe init cripples Defender preferences at volume scope and dropruns further stages from actor infrastructure:
hxxp://thesnapchatmodapk[.]com/wdd.bat
hxxp://thesnapchatmodapk[.]com/mine.bat
hxxp://thesnapchatmodapk[.]com/update1.exe
hxxp://thesnapchatmodapk[.]com/update2.exe
hxxp://thesnapchatmodapk[.]com/update3.exe
setup.exe pointed at the same host’s update2.exe / update3.exe. Once resident, the RAT wants browser cookies and passwords, autofill and cards, clipboard, Telegram tdata, Discord tokens, extension wallets, screenshots, and desktop files.
We Walked Into the Channel
On 2026-07-29 we used the recovered tokens and transmitted the following notice into the operator chats:
ATTENTION OPERATOR
This channel is under Intercept Cell control.
Cipher Cortex — Intercept Cell unit has seized operational custody of this bot infrastructure. Your Telegram C2 endpoints, bot tokens, and associated chat sessions are now monitored, logged, and retained as evidence.
We have:
• Identified your Millenium RAT builds and staging chain
• Mapped your exfiltration paths and secondary drop hosts
• Correlated victim telemetry to this command channel
• Notified affected parties and escalated to partner response teams
Continued use of this infrastructure will be treated as active targeting of monitored victims. Every command, upload, and callback from this point forward is observed.
You are no longer invisible.
You are no longer unattributed.
You are no longer in control of this channel.
Stand down.
Delete residual access.
Do not attempt further contact with victims tied to this campaign.
Intercept Cell is watching.
Cipher Cortex is documenting.
— Intercept Cell / Cipher Cortex
| Channel | Destination | Result | Evidence |
|---|---|---|---|
registeration.exe | @mr14maybot → -5150531439 | Delivered | HTTP 200, message_id 136695 |
installer.exe | @Billa2Bot_bot → -5180660112 | Delivered | HTTP 200, message_id 20522 |
setup.exe | token 8633556590:… → 8282123288 | Failed | Telegram 400 — Logged out |
Two of three channels accepted custody language in cleartext. One bot was already dead. The operators who still had sessions got the message the same way their victims’ machines would have — through the C2 they built.
The 7,258-Line Fiction
Buried in the RAR is a spreadsheet named like a jackpot: COMPANY.com - 7258 Line.xlsx (SHA-256 ef5adfc58fd3b699c6f1f9e2f4a2f6544cfb238f0e3d1e9c09c8082682b3bbce). The filename claims seven thousand rows. The sheet holds 108. Fields are ordinary USA contact columns — email, name, address, phone — with every source value pointed at the company’s public site. No wallets. No balances. No KYC. No transactions. It is bait formatting, not an investor book. We are not republishing the contact table.
Assessment
This is a leak-forum download farm wearing company branding. Zerodark’s zero-reputation profile, the dual lure (fake leads + fake Solidity tree), and the silent five-payload SFX are consistent with commodity Millenium distribution, not a targeted intrusion into the company itself. The company name is the hook. The product is stealer/RAT access.
We assess with high confidence that:
1. The distributed ZIP/SFX chain is malicious and matches Millenium RAT Builder v4.3 built by attat.
2. Telegram bots @mr14maybot and @Billa2Bot_bot were live C2 for this package on 2026-07-29, and both received our notice.
3. thesnapchatmodapk[.]com is actor staging for follow-on drops from this build.
4. The spreadsheet is decoy PII, not a genuine multi-thousand-row investor leak.
Defenders should refuse to execute the SFX, hunt the hashes and staging URLs below, report the named Telegram bots, and treat any host that ran the chain as fully compromised for browser and messenger secrets. Do not wholesale-block Telegram or GoFile — hunt the specific bots, tokens, and chat IDs.
IOC Summary
Archives
| Indicator | Type | Notes |
|---|---|---|
1936d151d4004ddb2d2d4ed144acd047c75ee6937edefa54bb2579ad67096b52 | SHA256 | Outer ZIP |
bcdc0ada0a466ff5c137d7093452a86a5094661560f1895db283c94ccd5603d6 | SHA256 | WinRAR SFX EXE (password 1212) |
ef5adfc58fd3b699c6f1f9e2f4a2f6544cfb238f0e3d1e9c09c8082682b3bbce | SHA256 | Bait XLSX (108 rows) |
Payloads
| Indicator | Type | Notes |
|---|---|---|
8098d0cf7a2460b14d7145b0c15a183c5fdbaa9e3932b1ee701aa4c2d59c0d9c | SHA256 | clip.exe clipboard stealer |
3b35d3233e08d7c7a43a0bc0a899ce14cd6797949e96af0c6b3c32f690ab4815 | SHA256 | crack.exe fake NexaSoft |
94ffe61fb9619a00d8c1066dc8728df2af733f0b9ca8783a93ecbe1e52e59562 | SHA256 | installer.exe Millenium (@Billa2Bot_bot) |
32e167e167c82f04b203c220b56edb95bbc3869254c7b792521a490c97e9507a | SHA256 | registeration.exe Millenium (@mr14maybot) |
748a02784c8a04459884778a66b2dbb5156b01b324c7b73f06c8058596d1a030 | SHA256 | setup.exe Millenium (token revoked) |
Network / C2
| Indicator | Type | Notes |
|---|---|---|
thesnapchatmodapk[.]com | Domain | Actor staging host |
hxxp://thesnapchatmodapk[.]com/wdd.bat | URL | Secondary drop |
hxxp://thesnapchatmodapk[.]com/mine.bat | URL | Secondary drop |
hxxp://thesnapchatmodapk[.]com/update1.exe | URL | Secondary drop |
hxxp://thesnapchatmodapk[.]com/update2.exe | URL | Secondary drop |
hxxp://thesnapchatmodapk[.]com/update3.exe | URL | Secondary drop |
@mr14maybot | Telegram bot | Live C2; notice delivered |
@Billa2Bot_bot | Telegram bot | Live C2; notice delivered |
-5150531439 | Telegram chat ID | @mr14maybot group |
-5180660112 | Telegram chat ID | Billabot group |
8282123288 | Telegram chat ID | setup.exe channel (bot logged out) |
8707453115:AAHcBGY-HkBvWdOgrgV0RrW3GeAyszNcFwQ | Telegram bot token | @mr14maybot |
8577105006:AAFIsVU-okV-VuC6iBL3hckQEAkVLfOFHyw | Telegram bot token | @Billa2Bot_bot |
8633556590:AAFPibTWDH-4E40BACytRmm88AnoXwwHnPk | Telegram bot token | setup.exe (revoked) |
Host / Tradecraft
| Indicator | Type | Notes |
|---|---|---|
fE5RNoV378Z2KsG6KG4CmTXf6v5lpKSW | XOR key | Millenium RCDATA decrypt (this build) |
WindowsHealthMonitor | Run-key / Startup name | clip.exe persistence label |
hxxps://raw[.]githubusercontent[.]com/attatier/Cloud/main/MilInfo.txt | URL | Builder staging (404 at analysis) |
hxxps://raw[.]githubusercontent[.]com/attatier/Cloud/main/Mil2.txt | URL | Builder staging (404 at analysis) |
C:\Users\attat\source\repos\Millenium RAT Builder V4.3\Stub\ | Builder path | Stub path artifact |
*Company brand names in the lure are redacted as COMPANY; hashes identify the original samples.*