New Malware Campaign Uses Phishing PowerShell FTP Infrastructure

www.news4hackers.com-new-malware-campaign-uses-phishing-powershell-ftp-infrastructure-new-malware-campaign-uses-phishing-powershell-ftp-infrastructure

Cybersecurity researchers have detected an ongoing Windows malware operation that utilizes FTP server greetings to conceal malicious commands, facilitating the deployment of two previously unknown remote access trojans, E4del and PINHOLE.

The Attack Chain Incorporates LNK Files, PowerShell, and SurveyMonkey

The attack chain incorporates LNK files, PowerShell scripting, and SurveyMonkey for command-and-control infrastructure. The campaign employs FTP server banners—text messages displayed during initial connections—to transmit hidden instructions to compromised systems. This method allows attackers to bypass traditional web-based command channels by embedding directives within the initial server response. The technique was first observed in July 2026 and remained active through August of the same year, with new infrastructure continuously emerging.

The Infection Process Begins with a ZIP Archive

The infection process begins with a ZIP archive containing a Windows shortcut file (LNK). Researchers suggest the initial compromise likely occurs via phishing attacks. When the LNK file is executed, it initiates a chain of events that connects to an FTP server. The server’s banner includes malicious commands, which are retrieved by the infected system. These commands trigger PowerShell scripts, effectively transforming the FTP server greeting into a remote instruction delivery mechanism.

E4del and PINHOLE Remote Access Trojans Delivered

The attack delivers two distinct remote access trojans: E4del and PINHOLE.

E4del: Node.js-Based Remote Access Trojan

E4del is a Node.js-based remote access trojan packaged within a digitally signed Electron application that mimics the Discord messaging platform. It enables attackers to execute commands through temporary or persistent shells, capture screenshots, and stream a victim’s desktop via WebSockets. Additionally, a Node.js module named crypto32.node was identified, which appears to be designed for privilege escalation, though researchers could not obtain the module for further analysis.

PINHOLE: Alternative Execution Path

PINHOLE follows an alternative execution path, retrieving its command-and-control configuration from SurveyMonkey survey questions and specific PINs. This approach enhances the malware’s resilience against infrastructure takedowns. To minimize its footprint, PINHOLE loads only a portion of its payload into memory at a time, injecting the final components into a suspended ApplicationFrameHost.exe process using Early Bird APC injection.

PINHOLE Supports Credential Theft and Multiple Remote Commands

PINHOLE is capable of executing 14 distinct commands, including file enumeration, uploading, and downloading. During the analysis period, researchers observed 11 active execution paths. The malware’s use of FTP banners provides attackers with an alternative to widely exploited web services such as X, GitHub, and YouTube. However, this method may be less covert, as connections to unfamiliar FTP servers could trigger network monitoring alerts. Despite this, the technique demonstrates versatility and could be adapted for other attack vectors, such as ClickFix-style social engineering campaigns.

Investigation and Ongoing Threat

The investigation also identified indicators of compromise to assist defenders in detecting malicious infrastructure and potential infections. The continuous emergence of new infrastructure suggests the campaign remains active as of the latest research observations.



About Author

en_USEnglish