Well, for me he is the worse skid ever.
Rat Name: njRAT 0.5.7B
C2 Servers: virtual-rome.at.ply.gg:1111, virtual-rome.at.ply.gg:62832
The file is zip archive which contains a two files. Glitcher.exe and glitcher_loader.exe The glitcher.exe is safe file which is the gdi.
Glitcher_loader is C# which contains an resource file with decryptor.
After you decrypt the file the results are njRAT
VirusTotal Scan → VirusTotal
He renamed his tunnel “njRAT”