The malware DLL has "https://locator.blueswan.io" in it, and various texts referring to "bs-worker" or Blueswan-worker. It's more like an internal codename.
Fun fact: the DLL also has various "C:\Users\akabos" strings, that being the "CTO" of this enterprise: https://ru.linkedin.com/in/akabos