FDMTP
- Malware type
- downloader
- Profile updated
- 2026-07-07 15:01:12
Targeted industries: government-and-public-sector financial-services technology-and-telecommunications
Context
FDMTP is a newly discovered hacking tool developed in .NET, used by Earth Preta. It functions as a simple malware downloader and is based on the TouchSocket framework over the Duplex Message Transport Protocol (DMTP). In one campaign, threat actors embedded FDMTP in the data section of a DLL. This allows it to be launched through DLL side-loading. The embedded network configurations are encoded and encrypted to enhance security and evade detection, utilizing Base64 and DES encryption methods. It has been observed to serve as a secondary control tool, often deployed by the PUBLOAD backdoor.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Fdmtp (report)
- Trend Micro — Earth Preta New Malware And Strategies (report)