
BlueBottle's FileZilla Impersonation Campaign Hides XMRig Behind Zero-Detection ZIP
A self-signed certificate and C2 domain registered on the same day anchor a multi-stage XMRig cryptominer campaign targeting the Democratic Republic of Congo. The operation combines an encrypted outer ZIP that evades all 76 scanning engines with Cloudflare-fronted infrastructure and an automated binder-ZIP build pipeline — tradecraft discipline well beyond typical commodity miner deployments.
A PE32 dropper bearing a self-signed "FileZilla FTP Client" code-signing certificate — its validity start date of 2025-12-24 matching, to the day, the registration date of the campaign's C2 domain filezilla.cc — sits at the centre of a multi-stage XMRig cryptominer delivery chain that CTX Team has tracked from January through June 2026.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read