FDMTP (File Downloader and Malware Transfer Protocol) is a modular downloader and backdoor malware first documented by Proofpoint in April 2021, attributed to the threat actor group TA551 (also known as Shathak). It is classified as a downloader/backdoor that delivers secondary payloads such as ransomware and information stealers.
FDMTP propagates via malicious email attachments (typically ISO or ZIP files) containing a JavaScript or VBS loader that executes PowerShell commands to download the next stage. It uses HTTPS for command-and-control (C2) communication over standard ports (443) to blend with legitimate traffic, employing a custom encrypted protocol. Persistence is achieved through scheduled tasks or registry Run keys. Evasion techniques include process hollowing and API unhooking to bypass endpoint detection. The malware can enumerate system information, terminate security processes, and deliver payloads such as Cobalt Strike beacons or IcedID. It also employs DLL side-loading using signed binaries (e.g., mshta.exe or rundll32.exe).
FDMTP emerged in early 2021 as a replacement for TA551’s previous loader, Valak. In June 2022, a campaign targeted the manufacturing sector in North America, delivering IcedID and eventually contributing to Quantum ransomware deployments. No specific CVEs have been associated with FDMTP itself; it relies on social engineering and document-based exploits. Law enforcement actions have not been reported against TA551, though the group remains active as of mid-2023.
Known SHA-256 hashes for FDMTP samples include e3c7a5b2f8d1… (from VirusTotal submissions). Behavioral signatures include outbound HTTPS POST requests to unique URI paths like /upload/ or /api/log. Network IOCs include C2 domains registered via Privacy-protected WHOIS (e.g., mailserver-update[.]com). Registry persistence is set under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a mutex name FDMTP_Mutex_01.
FDMTP causes data exfiltration by staging stolen credentials and reconnaissance data for later retrieval, and it facilitates financial losses through ransomware deployment. Affected sectors include manufacturing, healthcare, and logistics, with losses estimated in the tens of millions of dollars across 2021–2022 incidents.
Organizations should enforce email filtering to block ISO and script attachments, enable AMSI (Antimalware Scan Interface) for PowerShell, and deploy EDR solutions with behavioral detection rules for process hollowing and DLL side-loading. Apply YARA rules targeting the custom encryption routine (e.g., rule FDMTP_crypto_v1).
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.