FileZilla is a legitimate FTP client that threat actors abuse to exfiltrate data; it is not inherently malware. Its file-transfer functionality enables attackers to move stolen organizational information to external destinations using protocols outside their command-and-control channels. Such abuse has been mapped to MITRE ATT&CK T1048.003, Exfiltration Over Unencrypted Non-C2 Protocol.
FileZilla has been identified as an exfiltration tool in ransomware intrusions involving Akira and Fog, alongside alternatives such as WinSCP and Rclone. In these operations, legitimate file-transfer software supports data theft that can provide additional leverage for extortion. FileZilla's observed role is data transfer, not ransomware encryption or initial compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The report describes FileZilla as an uncommon but unsurprising choice for data exfiltration and lists it among atypical tools leveraged by groups such as Inc Ransom.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Associated Tools • FileZilla where not expected (file transfer)
Karakurt actors have used FTP services, including Filezilla, to exfiltrate data from victims' networks.
~77 Go de données exfiltrés via FileZilla (SFTP) vers 185.174.100.203:22 en deux sessions
After creating archives containing collected files, affiliates used different softwares to exfiltrate several gigabytes of data: WinSCP and FileZilla.
The attacker’s first exfiltration method was conventional: FileZilla and FTP to an external IP address. Egress filtering blocked the attempt.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
FTP client abused for data transfer/exfiltration during the intrusions.
Legitimate open-source file-transfer software abused to transfer data between compromised devices and remote servers. Its graphical interface, support for protocols such as SFTP, and cross-platform availability facilitate attacker use.
FTP client referenced as being used by threat actors for data transfer/exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.