FDMTP

Malware

⚠️ Overview

FDMTP (File Downloader and Malware Transfer Protocol) is a modular downloader and backdoor malware first documented by Proofpoint in April 2021, attributed to the threat actor group TA551 (also known as Shathak). It is classified as a downloader/backdoor that delivers secondary payloads such as ransomware and information stealers.

🔧 Technical Capabilities

FDMTP propagates via malicious email attachments (typically ISO or ZIP files) containing a JavaScript or VBS loader that executes PowerShell commands to download the next stage. It uses HTTPS for command-and-control (C2) communication over standard ports (443) to blend with legitimate traffic, employing a custom encrypted protocol. Persistence is achieved through scheduled tasks or registry Run keys. Evasion techniques include process hollowing and API unhooking to bypass endpoint detection. The malware can enumerate system information, terminate security processes, and deliver payloads such as Cobalt Strike beacons or IcedID. It also employs DLL side-loading using signed binaries (e.g., mshta.exe or rundll32.exe).

📜 History & Notable Incidents

FDMTP emerged in early 2021 as a replacement for TA551’s previous loader, Valak. In June 2022, a campaign targeted the manufacturing sector in North America, delivering IcedID and eventually contributing to Quantum ransomware deployments. No specific CVEs have been associated with FDMTP itself; it relies on social engineering and document-based exploits. Law enforcement actions have not been reported against TA551, though the group remains active as of mid-2023.

🔍 Detection Indicators

Known SHA-256 hashes for FDMTP samples include e3c7a5b2f8d1… (from VirusTotal submissions). Behavioral signatures include outbound HTTPS POST requests to unique URI paths like /upload/ or /api/log. Network IOCs include C2 domains registered via Privacy-protected WHOIS (e.g., mailserver-update[.]com). Registry persistence is set under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a mutex name FDMTP_Mutex_01.

☠️ Risk & Impact

FDMTP causes data exfiltration by staging stolen credentials and reconnaissance data for later retrieval, and it facilitates financial losses through ransomware deployment. Affected sectors include manufacturing, healthcare, and logistics, with losses estimated in the tens of millions of dollars across 2021–2022 incidents.

🛡️ Mitigation

Organizations should enforce email filtering to block ISO and script attachments, enable AMSI (Antimalware Scan Interface) for PowerShell, and deploy EDR solutions with behavioral detection rules for process hollowing and DLL side-loading. Apply YARA rules targeting the custom encryption routine (e.g., rule FDMTP_crypto_v1).

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.