Threat actors are exploiting FTP banners to conceal commands for deploying two undocumented remote access trojans (RATs), E4del and PINHOLE. This method was first observed by MalwareHunterTeam in July 2026, using shortcut files (.LNK) and FTP server banners as dead-drop resolvers to retrieve malicious commands. SOCRadar confirmed that this technique has been weaponized since early July 2026 and remains active, with new infrastructure identified as recently as August 2026. The attacks typically start with a ZIP archive leading to an LNK-based infection chain, likely initiated through phishing tactics.
E4del is a Node.js-based RAT disguised within a digitally signed Electron application mimicking Discord, capable of executing commands, capturing screenshots, streaming desktops, and downloading additional payloads. It also includes a module for privilege escalation. PINHOLE retrieves its command and control configuration from Pinterest and SurveyMonkey, designed to leave a minimal footprint and employing shellcode fluctuation. It supports 14 commands, including file management and credential theft, but had only recorded 11 execution events at the time of analysis.
SOCRadar notes that while using FTP banners is a novel approach, it is less stealthy than traditional web-based dead-drop resolvers. They provide indicators of compromise to help identify malicious infrastructure and infected machines.