
BlueBottle Hides Cryptominer in Fake FileZilla Update Targeting DRC
A typosquatted domain impersonating the FileZilla FTP client is delivering a two-stage dropper-binder chain to targets in the Democratic Republic of Congo. The operation beacons to the hashvault.pro cryptomining pool and deploys BitRAT-family implants, with every executable stage hardened by layered sandbox evasion. CTX Team attributes the campaign to BlueBottle, a threat actor with dual espionage and financial motivations.
A typosquatted domain impersonating the FileZilla FTP client is serving a two-stage dropper-binder chain to targets in the Democratic Republic of Congo — an operation that pairs brand-impersonation lures with layered sandbox evasion baked into every executable stage, while beaconing to the hashvault.pro cryptomining pool over a CoinMiner JA3 TLS fingerprint.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read