Cybersecurity researchers have identified a new campaign that leverages FTP banners as dead drop resolvers (DDRs) to distribute two new remote access trojans (RATs), named E4del and PINHOLE. This method involves using the welcome message an FTP server sends upon connection to deliver commands to malware stagers.
While threat actors commonly abuse legitimate services for command-and-control (C2) infrastructure, this marks the first documented instance of FTP banners being used for this purpose in the wild. Although less stealthy than traditional web-based DDRs, this technique represents an unusual and notable development in malware delivery tactics.
One attack chain observed involves Spanish-language lures, tricking users into executing a Windows Shortcut (LNK) file. This LNK then fetches the next-stage command from an FTP banner, which subsequently connects to a WebDAV server to download and execute a DLL export. This WebDAV approach has also been linked to ClearFake campaigns distributing other malware.
The E4del RAT, delivered via a multi-stage process involving multiple FTP banners, is Node.js-based and disguised as a digitally signed Electron application mimicking Discord. It possesses capabilities such as defense evasion, persistence, system fingerprinting, and encrypted C2 communication. E4del can facilitate an interactive reverse shell, screenshot capture, live desktop streaming, file downloads, and additional payload delivery.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A new cyber campaign is using FTP banners as dead drop resolvers to deliver two previously undocumented remote access trojans (RATs), E4del and PINHOLE. This technique, while less stealthy than web-based methods, marks the first time FTP banners have been observed in the wild for C2 infrastructure, indicating an evolving threat landscape.