Skip to main content
Mallory
Back to intelligence
remote-access-implantphishing-campaign-intelligenceloader-delivery-mechanismdefense-evasion-method

DLL Sideloading Campaigns Spread RATs via Fake FileZilla and Tax Phishing Lures

Updated 12d agoFirst seen Apr 11, 20263 sources

Attackers distributed remote-access malware through two distinct delivery chains: a fake FileZilla website serving trojanized installers and phishing emails impersonating South Korea’s National Tax Service. In the FileZilla campaign, victims received either a portable archive containing a malicious version.dll for DLL sideloading or a bundled installer that deployed legitimate FileZilla alongside a rogue DLL in the install path. The malware acted as a multi-stage loader, decrypting payloads in memory before launching a RAT that could steal credentials, log keystrokes, capture screenshots, and provide HVNC-based remote control. The operators also used DNS-over-HTTPS to Cloudflare’s resolver to look up welcome.supp0v3[.]com, likely to reduce visibility to DNS-based defenses, and included anti-analysis checks for VMware and VirtualBox environments.

In the tax-themed campaign, recipients were lured to spoofed tax-notice pages and prompted to download a ZIP archive containing a legitimate signed Intel executable, a malicious sideloaded DLL, and an encrypted BIN payload. The malware decrypted shellcode and a RAT/backdoor from vulkan-1.bin using a modified RC4 routine, then established persistence through a service named "Microsoft Compatibility system". Researchers said the backdoor supports remote control, privilege escalation, process injection, file theft, and lateral movement over RPC. Infrastructure analysis linked the activity to multiple variants and multilingual lures, including impersonation of tax and court authorities in Malaysia and India, indicating an organized, evolving multi-country operation.

Share:
DLL Sideloading Campaigns Spread RATs via Fake FileZilla and Tax Phishing Lures
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Mar 24, 20262mo ago

Researchers link tax-phishing malware to broader ongoing campaign

Analysis of the malware and infrastructure identified multiple variants, multilingual phishing content, and persistence via a service named "Microsoft Compatibility system." The report assessed the activity as an ongoing campaign that continues to be updated and supports remote control, privilege escalation, process injection, file theft, and lateral movement via RPC.

South Korea tax-investigation phishing campaign distributes backdoor

A phishing campaign impersonating South Korea's National Tax Service was observed sending fake tax investigation notices to corporate users. Victims were directed to a spoofed page and prompted to download a ZIP archive containing a legitimate signed Intel executable, a malicious sideloaded DLL, and an encrypted BIN payload.

Mar 13, 20263mo ago

Alyac documents FileZilla malware campaign technical details

Researchers reported that the FileZilla-themed malware used a multi-stage loader, DNS-over-HTTPS to Cloudflare's resolver to reach the C2 domain welcome.supp0v3[.]com, anti-VM checks, and a final RAT capable of credential theft, keylogging, screenshots, and HVNC-based remote control.

Fake FileZilla site used to distribute trojanized installers

Attackers set up a fake website impersonating the official FileZilla site to distribute malware through trojanized installers. The campaign used both a portable archive with a malicious version.dll for DLL sideloading and a single executable that installed legitimate FileZilla while dropping a malicious DLL.

Mar 4, 20263mo ago

Malwarebytes identifies trojanized FileZilla site and portable installer

Malwarebytes reported a campaign using the fake domain filezilla-project[.]live to distribute a trojanized portable FileZilla 3.69.5 package. The installer abused DLL sideloading via a malicious version.dll to steal saved FTP credentials and communicate with command-and-control infrastructure.

Trojanized FileZilla FTP Client Targets Developer Credentials via DLL Sideloading • Daily CyberSecurity
Dec 15, 20256mo ago

Multi-country tax-themed phishing campaign begins

A malware campaign using tax and legal notification lures began around mid-December 2025, targeting users with spoofed government-themed messages. Related content and infrastructure indicate activity spanning South Korea, Malaysia, and India.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

10 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.