C&CMembers
C&C

Decade-Old Firefox Impersonator Resurfaces in 2026 C2 Feed

A 139KB unsigned executable spoofing Firefox 40.0.3, built in November 2015, has turned up in a command-and-control indicator set logged from February to August 2026. Tagged with the aging 'waledac' label, the file shares no build fingerprints with the eight scattered, low-reputation IPs bundled alongside it.

Aug 28, 2026, 14:49 (UTC+9)Last seenAug 28, 2026Severity100ByCTX TeamIOC11MITRE14RegionsUS

A 139-kilobyte Windows executable that dresses itself up as Firefox 40.0.3 — spoofing the product name, internal name and copyright string of Mozilla's own build metadata while carrying no digital signature at all — has surfaced inside a command-and-control indicator set first logged on 2026-02-05 and still being tracked through 2026-08-28. The file itself is nothing new: its earliest submission dates to 2015-12-10, a full decade before the rest of this record's sighting window opens.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence