FileTour is a malware family used as a Russian pay-per-install platform and downloader within the broader Stantinko criminal ecosystem. It has been associated with distribution operations targeting users seeking pirated software and game installers, where executable packages masquerade as legitimate downloads but instead install unwanted software and additional malware. FileTour has been linked to platforms such as MoneyInst and InstallRed and has served as an entry point for Stantinko infections.
Its primary role is to fetch and install follow-on payloads rather than act as the final monetization component. Observed payloads include potentially unwanted applications, browser-related adware, click-fraud components, and Adstantinko, which in turn deploys Stantinko’s persistent services and malicious browser extensions. Through this chain, FileTour contributes to ad injection, traffic redirection, and broader botnet enablement. It has also been tied to click-fraud doorway infrastructure used to funnel victims through monetized redirection paths.
FileTour is associated mainly with Windows-based infection chains and supports a criminal business model centered on pay-per-install distribution, ad fraud, and malware delivery. In the Stantinko context, it functions as the initial access and malware delivery layer that enables subsequent persistence and monetization by downstream components.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Components that are left on disk employ a custom code obfuscator that mangles strings and applies control flow flattening.
33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
FileTour is referenced as a Stantinko-related click-fraud component tied to doorway websites and Bitly redirections.
FileTour is referenced as a click-fraud component/campaign associated with the broader Stantinko activity, using doorway websites and Bitly redirections.
Downloader malware distributed as fake pirated software or disguised torrent-related executables. It retrieves and installs multiple payloads including PUAs, click-fraud malware, and Adstantinko/Stantinko components.
Mentioned only as a comparison example of click-fraud activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.