Experts are warning users to download the FTP client, FileZilla, only from trusted websites, as cybercriminals are distributing fake versions in an attempt to steal users' credentials.
According to Avast researchers, malicious versions of the program are mostly hosted on compromised websites. Unfortunately, there is not much evidence to suggest that the client has been tampered with, other than the file size and an extra DLL or two.
The fake FileZilla works normally, except that it cannot receive updates, likely in an attempt by the attackers to prevent users from replacing the malicious files. Once the malware is installed on a computer, it steals the user's FTP credentials and uploads them to a remote server.
Cybercriminals can misuse FTP usernames and passwords in several ways: either by using compromised FTP servers to host malware, or by stealing valuable data stored on them.
Additional technical details about this attack are available on the Avast blog.

