Fake FileZilla Downloads Spread RAT via Stealthy Multi-Stage Loader
ID: 07d89d57-7a70-5006-9ec5-710f36b08c4b
STIX ID: report--07d89d57-7a70-5006-9ec5-710f36b08c4b
Feed Name: GBHackers
A malicious campaign is delivering a stealthy Remote Access Trojan by cloning the FileZilla download page and bundling a malicious DLL with legitimate installers or portable builds. The DLL performs sideloading and launches a multi-stage, in-memory loader that uses anti-analysis checks and DNS-over-HTTPS (Cloudflare) for C2, enabling credential theft, keylogging, screen capture, and full remote control; defenders are advised to restrict downloads to official domains, enforce application control, monitor for suspicious DLLs, and inspect/limit DoH traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
