Attackers Use FTP Banners to Deliver New Windows RATs
π Threat actors are embedding commands in FTP server banners to deliver two new remote access trojans, E4del and PINHOLE, observed in attacks since July 2026. The campaign begins with a ZIP archive and LNK-based infection chain, likely introduced via phishing, and uses FTP banners as dead-drop resolvers to retrieve PowerShell stagers. SOCRadar discovered the technique and highlights indicators of compromise to help defenders identify affected systems. E4del is a Node.js RAT masquerading as Discord, while PINHOLE uses Pinterest and SurveyMonkey for C2 resilience.
