started · updated
Hackers use FTP server banners to deliver E4del and PINHOLE malware
Threat actors are utilizing FTP server banners as dead-drop resolvers to deliver two new remote access trojans (RATs) named E4del and PINHOLE. Researchers at SOCRadar observed this technique, which involves embedding malicious PowerShell commands within the text strings used by FTP servers as greeting messages before a user logs in.
The attack chain typically begins when a user opens a shortcut (.LNK) file contained within a ZIP archive, often via phishing. This file connects to a compromised FTP server to retrieve commands from the banner, initiating the infection.
E4del is a Node.js-based RAT packaged inside a digitally signed Electron application designed to masquerade as Discord. It allows attackers to run commands through shells, capture screenshots, and stream desktops via WebSockets. PINHOLE is a multi-stage loader that resolves encrypted command-and-control (C2) settings using Pinterest and SurveyMonkey, eventually relaying traffic through Cloudflare Workers to inject a final RAT into a suspended process.
Entities
Cloudflare · E4del · PINHOLE · SOCRadar · Windows