Attackers distributed remote-access malware through two distinct delivery chains: a fake FileZilla website serving trojanized installers and phishing emails impersonating South Korea’s National Tax Service. In the FileZilla campaign, victims received either a portable archive containing a malicious version.dll for DLL sideloading or a bundled installer that deployed legitimate FileZilla alongside a rogue DLL in the install path. The malware acted as a multi-stage loader, decrypting payloads in memory before launching a RAT that could steal credentials, log keystrokes, capture screenshots, and provide HVNC-based remote control. The operators also used DNS-over-HTTPS to Cloudflare’s resolver to look up welcome.supp0v3[.]com, likely to reduce visibility to DNS-based defenses, and included anti-analysis checks for VMware and VirtualBox environments.
In the tax-themed campaign, recipients were lured to spoofed tax-notice pages and prompted to download a ZIP archive containing a legitimate signed Intel executable, a malicious sideloaded DLL, and an encrypted BIN payload. The malware decrypted shellcode and a RAT/backdoor from vulkan-1.bin using a modified RC4 routine, then established persistence through a service named "Microsoft Compatibility system". Researchers said the backdoor supports remote control, privilege escalation, process injection, file theft, and lateral movement over RPC. Infrastructure analysis linked the activity to multiple variants and multilingual lures, including impersonation of tax and court authorities in Malaysia and India, indicating an organized, evolving multi-country operation.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Analysis of the malware and infrastructure identified multiple variants, multilingual phishing content, and persistence via a service named "Microsoft Compatibility system." The report assessed the activity as an ongoing campaign that continues to be updated and supports remote control, privilege escalation, process injection, file theft, and lateral movement via RPC.
A phishing campaign impersonating South Korea's National Tax Service was observed sending fake tax investigation notices to corporate users. Victims were directed to a spoofed page and prompted to download a ZIP archive containing a legitimate signed Intel executable, a malicious sideloaded DLL, and an encrypted BIN payload.
Researchers reported that the FileZilla-themed malware used a multi-stage loader, DNS-over-HTTPS to Cloudflare's resolver to reach the C2 domain welcome.supp0v3[.]com, anti-VM checks, and a final RAT capable of credential theft, keylogging, screenshots, and HVNC-based remote control.
Attackers set up a fake website impersonating the official FileZilla site to distribute malware through trojanized installers. The campaign used both a portable archive with a malicious version.dll for DLL sideloading and a single executable that installed legitimate FileZilla while dropping a malicious DLL.
Malwarebytes reported a campaign using the fake domain filezilla-project[.]live to distribute a trojanized portable FileZilla 3.69.5 package. The installer abused DLL sideloading via a malicious version.dll to steal saved FTP credentials and communicate with command-and-control infrastructure.
A malware campaign using tax and legal notification lures began around mid-December 2025, targeting users with spoofed government-themed messages. Related content and infrastructure indicate activity spanning South Korea, Malaysia, and India.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
blog.alyac.co.kr
Open sourceblog.alyac.co.kr
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.