Trojanized FileZilla FTP Client Targets Developer Credentials via DLL Sideloading
ID: 0a57fed7-13c4-5d1a-9396-679535552db9
STIX ID: report--0a57fed7-13c4-5d1a-9396-679535552db9
Feed Name: securityonline.info
Malwarebytes researchers discovered a campaign distributing a trojanized FileZilla 3.69.5 portable package from a spoofed site (filezilla-project.live). The attack abuses Windows DLL search order by including a malicious version.dll in the portable bundle, which runs inside FileZilla to steal saved FTP credentials and contact C2 over DNS-over-HTTPS; the malware also includes anti-analysis checks, process injection, persistence, and potential data encryption. Users are advised to download only from the official site, verify hashes, remove any version.dll found in FileZilla folders, and monitor non-browser DoH traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
