Fake FileZilla Downloads Lead to RAT Infections Through Stealthy Multi-Stage Loader
ID: 71b0c05d-9677-57b7-a0a5-c4470fcd261c
STIX ID: report--71b0c05d-9677-57b7-a0a5-c4470fcd261c
Feed Name: cybersecurityNews.com
A coordinated malware campaign impersonates the FileZilla download site to distribute a Remote Access Trojan by bundling a malicious DLL with legitimate installers (via DLL sideloading or a packed executable). The malware uses a four-stage in-memory loader, DNS-over-HTTPS to Cloudflare for C2 (welcome.supp0v3.com), anti-sandbox checks, and provides credential theft, keylogging, screenshots, and HVNC remote control; several MD5s, a domain, URL, and IP:port are published as IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
