Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
FTP Banners Used for New Malware Delivery Tactics

FTP Banners Used for New Malware Delivery Tactics

Posted on August 25, 2026 By CWS

Cybersecurity experts have identified a novel tactic using FTP banners as dead drop resolvers (DDRs) to distribute two newly discovered remote access trojans (RATs), named E4del and PINHOLE. This innovative approach marks the first instance of such a technique being observed in active cyber threat campaigns.

Mechanism of FTP Banner Exploitation

FTP banners, typically used as greeting messages by FTP servers, are being manipulated to deploy malware commands. SOCRadar, a cybersecurity firm, detailed that this method involves malware stagers extracting commands from the initial FTP response. This technique, although less covert than web-based DDRs, can trigger alerts when connecting to unfamiliar FTP servers.

A particular attack sequence employs Spanish-language baits related to voucher claims to mislead users into running a Windows Shortcut (LNK). This action retrieves further commands from an FTP banner, which connects to a WebDAV server. Subsequently, a DLL is executed via “rundll32.exe” using conhost, illustrating the complexity of this method.

Detailed Examination of Attack Chains

In addition to FTP banners, attackers utilize WebDAV in campaigns like ClearFake, which Microsoft and Gen Threat Labs have reported. These operations use compromised websites to distribute malware by enticing users with fake CAPTCHA challenges. SOCRadar identified a specific FTP address, “157.254.194[.]31:21,” that initiates a multi-step delivery chain, downloading a Node.js-based RAT, E4del, disguised as a Discord application.

E4del is capable of evasion, persistence, and encrypted communication, enabling functions such as reverse shell access and live desktop streaming. The RAT operates dynamically, adjusting its activity levels based on elapsed time since its last command.

PINHOLE RAT and Advanced Techniques

The second RAT, PINHOLE, employs more sophisticated methods, using reputable platforms like Pinterest for DDRs and relaying communications via Cloudflare Workers. Commands from its FTP banner involve using MSXML2.XMLHTTP in PowerShell to execute scripts discreetly, minimizing forensic footprints.

PINHOLE also utilizes a unique injection technique, bypassing security measures through a suspended process and asynchronous procedure calls (APCs). Its functionalities include file exfiltration, process management, and PowerShell command execution, revealing its extensive capabilities.

The attackers have an “FTP Stats Panel” for monitoring campaign success, although only 11 executions suggest this is an emerging threat. This innovative use of FTP banners for malware delivery reflects a creative shift in tactics, with potential for adaptation in future campaigns.

The Hacker News Tags:C2 infrastructure, cyber threat, Cybersecurity, E4del, FTP banners, malware campaign, malware delivery, PINHOLE, RAT, remote access trojan

Post navigation

Previous Post: Alice Secures $140 Million to Combat AI Threats
Next Post: CISA Red Team Uncovers Security Flaws in Critical Infrastructure

Related Posts

Black Basta Ransomware Leader Added to EU Most Wanted and INTERPOL Red Notice Black Basta Ransomware Leader Added to EU Most Wanted and INTERPOL Red Notice The Hacker News
Mythos’ Impact on Exposure Windows in Security Programs Mythos’ Impact on Exposure Windows in Security Programs The Hacker News
Cisco Fixes Actively Exploited Zero-Day CVE-2026-20045 in Unified CM and Webex Cisco Fixes Actively Exploited Zero-Day CVE-2026-20045 in Unified CM and Webex The Hacker News
AsyncRAT Exploits ConnectWise ScreenConnect to Steal Credentials and Crypto AsyncRAT Exploits ConnectWise ScreenConnect to Steal Credentials and Crypto The Hacker News
GitHub Actions Compromised to Steal CI/CD Credentials GitHub Actions Compromised to Steal CI/CD Credentials The Hacker News
Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting Provider Massive 7.3 Tbps DDoS Attack Delivers 37.4 TB in 45 Seconds, Targeting Hosting Provider The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Redefines Vulnerability Management in Cybersecurity
  • Microsoft Teams Exploited in SynkLoader Cyber Attacks
  • U.S. Targets Iran-Linked Cybercriminals with Sanctions
  • CISA Red Team Uncovers Security Flaws in Critical Infrastructure
  • FTP Banners Used for New Malware Delivery Tactics

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Redefines Vulnerability Management in Cybersecurity
  • Microsoft Teams Exploited in SynkLoader Cyber Attacks
  • U.S. Targets Iran-Linked Cybercriminals with Sanctions
  • CISA Red Team Uncovers Security Flaws in Critical Infrastructure
  • FTP Banners Used for New Malware Delivery Tactics

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark