APTMembers
APT

Signed FileZilla Installer Hides Adware Bundler Behind Valid Sectigo Chain

A file posing as a FileZilla installer carries a fully valid, unrevoked Sectigo/Tim Kosse code-signing chain while 12 of 75 antivirus engines classify it as adware.bundler/filezilla. The mismatch between clean signing credentials and an active detection tail defines a sponsored-bundler distribution pattern, not a compromise of FileZilla's real build infrastructure.

Jun 8, 2026, 23:36 (UTC+9)Last seenJul 2, 2026Severity100ByCTX TeamActorAPT28StrontiumIOC7MITRE9

A file calling itself FileZilla_3.69.5_win32-setup.exe is circulating with a complete, currently-valid Sectigo code-signing chain — Tim Kosse through Sectigo Public Code Signing CA R36, Sectigo Public Code Signing Root R46, and the Sectigo (AAA) root — even as 12 of 75 antivirus engines classify it as adware.bundler/filezilla.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence