logo

A fake FileZilla site hosts a malicious download

ID: 8a3209bc-cabf-53e7-93e3-72a04dc9fd29

STIX ID: report--8a3209bc-cabf-53e7-93e3-72a04dc9fd29

Feed Name: Malwarebytes Blog

Threat Score
72/100

Date Published: 2026-03-02

Date Updated: 2026-04-28

...
...

A trojanized portable copy of FileZilla 3.69.5 is being distributed from a lookalike domain (filezilla-project.live); the archive contains a malicious version.dll that uses DLL search order hijacking to load inside filezilla.exe, harvest saved FTP credentials, and call back to C2 infrastructure via DNS-over-HTTPS (welcome.supp0v3.com) and a secondary TCP server at 95.216.51.236:31415. The loader includes anti-analysis checks, proxying behavior, and persistence-related actions; Malwarebytes provides hashes, domains, and network indicators and recommends verifying official downloads, checking for version.dll in FileZilla folders, and blocking the listed IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.