Hackers Exploit FTP Server Banners to Target Windows Systems with New Malware

www.news4hackers.com-hackers-exploit-ftp-server-banners-to-target-windows-systems-with-new-malware-hackers-exploit-ftp-server-banners-to-target-windows-systems-with-new-malware

Cybersecurity researchers reveal a new method where hackers use FTP server banners to deploy malicious payloads, targeting Windows systems with E4del and PINHOLE RATs.

Discovery and Methodology

E4del and PINHOLE threat actors have developed a novel method to distribute malicious payloads by embedding commands within FTP server banners, according to cybersecurity researchers. This technique involves leveraging the initial greeting message sent by FTP servers to deliver instructions for two remote access trojans (RATs) identified as E4del and PINHOLE.

Initial Discovery

The discovery was made by MalwareHunterTeam during an investigation into a July 2026 attack that utilized shortcut files (.LNK) and FTP server banners as dead-drop resolvers (DDR) to execute malicious operations. FTP banners function as text-based greetings exchanged between servers and clients before authentication. Attackers manipulate this protocol to embed malicious commands in the initial response, enabling a malware stager to receive instructions from a remote server.

Attack Chain and Malware Details

SOCRadar, a threat intelligence platform, expanded its analysis after detecting this method during an investigation and confirmed its continued use through August 2026. The researchers noted that the technique has been active since early July 2026, with new infrastructure observed in the latest campaigns.

Infection Routes

The attack chain begins with a ZIP archive triggering an LNK-based infection sequence, which researchers believe originates from phishing activities. Two distinct infection routes deliver E4del and PINHOLE via PowerShell scripts retrieved from FTP banners.

Malware Capabilities

E4del is a Node.js-based RAT packaged within a digitally signed Electron application disguised as Discord. It supports command execution through persistent or temporary shells, screenshot capture, and desktop streaming via WebSockets. A Node.js module named crypto32.node is associated with privilege escalation attempts, though researchers could not fully analyze its functionality.

PINHOLE, another RAT, obtains its command-and-control (C2) configuration from physical pins and SurveyMonkey survey questions, providing resilience against takedown efforts. The malware employs a minimal footprint by using shellcode fluctuation to maintain only a 4KB payload segment in memory at any time. It injects the final assembly into a suspended ApplicationFrameHost.exe process using Early Bird APC injection. PINHOLE supports 14 commands, including file enumeration, uploading, and execution.

Limitations and Adaptability

While the use of FTP banners for command delivery is unconventional, SOCRadar highlights its limitations compared to traditional web-based DDRs like X, GitHub, or YouTube. FTP connections to unfamiliar servers are more likely to trigger alerts, as they lack the high-volume traffic patterns of legitimate services. However, the technique’s versatility could enable adaptation for social engineering campaigns like ClickFix.

Indicators of Compromise and Defense

SOCRadar’s report includes indicators of compromise (IOCs) to help organizations detect malicious infrastructure and compromised systems. The analysis also reveals that 37% of threat actor actions are blocked when valid credentials are present. The Blue Report 2026, which evaluates defense mechanisms across 338 million simulations, underscores the importance of detecting such novel attack vectors.

Conclusion

E4del and PINHOLE represent evolving threats that exploit protocol weaknesses and legitimate software components. Their deployment methods highlight the need for continuous monitoring of network traffic and anomaly detection to counter emerging malware delivery techniques.

According to cybersecurity researchers, this technique involves leveraging the initial greeting message sent by FTP servers to deliver instructions for two remote access trojans (RATs) identified as E4del and PINHOLE.


Blog Image

About Author

en_USEnglish