APTMembers
APT

BlueBottle's FileZilla Impersonation Campaign Hides XMRig Behind Zero-Detection ZIP

A self-signed certificate and C2 domain registered on the same day anchor a multi-stage XMRig cryptominer campaign targeting the Democratic Republic of Congo. The operation combines an encrypted outer ZIP that evades all 76 scanning engines with Cloudflare-fronted infrastructure and an automated binder-ZIP build pipeline — tradecraft discipline well beyond typical commodity miner deployments.

Jun 7, 2026, 23:07 (UTC+9)Last seenJun 8, 2026Severity98ByCTX TeamActorBlueBottleOpera1erIOC23MITRE29RegionsCD

A PE32 dropper bearing a self-signed "FileZilla FTP Client" code-signing certificate — its validity start date of 2025-12-24 matching, to the day, the registration date of the campaign's C2 domain filezilla.cc — sits at the centre of a multi-stage XMRig cryptominer delivery chain that CTX Team has tracked from January through June 2026.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence