
Decade-Old Firefox Impersonator Resurfaces in 2026 C2 Feed
A 139KB unsigned executable spoofing Firefox 40.0.3, built in November 2015, has turned up in a command-and-control indicator set logged from February to August 2026. Tagged with the aging 'waledac' label, the file shares no build fingerprints with the eight scattered, low-reputation IPs bundled alongside it.
A 139-kilobyte Windows executable that dresses itself up as Firefox 40.0.3 — spoofing the product name, internal name and copyright string of Mozilla's own build metadata while carrying no digital signature at all — has surfaced inside a command-and-control indicator set first logged on 2026-02-05 and still being tracked through 2026-08-28. The file itself is nothing new: its earliest submission dates to 2015-12-10, a full decade before the rest of this record's sighting window opens.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read