APTMembers
APT

BlueBottle Hides Cryptominer in Fake FileZilla Update Targeting DRC

A typosquatted domain impersonating the FileZilla FTP client is delivering a two-stage dropper-binder chain to targets in the Democratic Republic of Congo. The operation beacons to the hashvault.pro cryptomining pool and deploys BitRAT-family implants, with every executable stage hardened by layered sandbox evasion. CTX Team attributes the campaign to BlueBottle, a threat actor with dual espionage and financial motivations.

Jun 15, 2026, 10:27 (UTC+9)Last seenJun 15, 2026Severity77ByCTX TeamActorBlueBottleOpera1erIOC8MITRE18RegionsCD

A typosquatted domain impersonating the FileZilla FTP client is serving a two-stage dropper-binder chain to targets in the Democratic Republic of Congo — an operation that pairs brand-impersonation lures with layered sandbox evasion baked into every executable stage, while beaconing to the hashvault.pro cryptomining pool over a CoinMiner JA3 TLS fingerprint.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence