Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
FTP Banners Used for New Malware Delivery Tactics

FTP Banners Used for New Malware Delivery Tactics

Posted on August 25, 2026 By CWS

Cybersecurity experts have identified a novel tactic using FTP banners as dead drop resolvers (DDRs) to distribute two newly discovered remote access trojans (RATs), named E4del and PINHOLE. This innovative approach marks the first instance of such a technique being observed in active cyber threat campaigns.

Mechanism of FTP Banner Exploitation

FTP banners, typically used as greeting messages by FTP servers, are being manipulated to deploy malware commands. SOCRadar, a cybersecurity firm, detailed that this method involves malware stagers extracting commands from the initial FTP response. This technique, although less covert than web-based DDRs, can trigger alerts when connecting to unfamiliar FTP servers.

A particular attack sequence employs Spanish-language baits related to voucher claims to mislead users into running a Windows Shortcut (LNK). This action retrieves further commands from an FTP banner, which connects to a WebDAV server. Subsequently, a DLL is executed via “rundll32.exe” using conhost, illustrating the complexity of this method.

Detailed Examination of Attack Chains

In addition to FTP banners, attackers utilize WebDAV in campaigns like ClearFake, which Microsoft and Gen Threat Labs have reported. These operations use compromised websites to distribute malware by enticing users with fake CAPTCHA challenges. SOCRadar identified a specific FTP address, “157.254.194[.]31:21,” that initiates a multi-step delivery chain, downloading a Node.js-based RAT, E4del, disguised as a Discord application.

E4del is capable of evasion, persistence, and encrypted communication, enabling functions such as reverse shell access and live desktop streaming. The RAT operates dynamically, adjusting its activity levels based on elapsed time since its last command.

PINHOLE RAT and Advanced Techniques

The second RAT, PINHOLE, employs more sophisticated methods, using reputable platforms like Pinterest for DDRs and relaying communications via Cloudflare Workers. Commands from its FTP banner involve using MSXML2.XMLHTTP in PowerShell to execute scripts discreetly, minimizing forensic footprints.

PINHOLE also utilizes a unique injection technique, bypassing security measures through a suspended process and asynchronous procedure calls (APCs). Its functionalities include file exfiltration, process management, and PowerShell command execution, revealing its extensive capabilities.

The attackers have an “FTP Stats Panel” for monitoring campaign success, although only 11 executions suggest this is an emerging threat. This innovative use of FTP banners for malware delivery reflects a creative shift in tactics, with potential for adaptation in future campaigns.

The Hacker News Tags:C2 infrastructure, cyber threat, Cybersecurity, E4del, FTP banners, malware campaign, malware delivery, PINHOLE, RAT, remote access trojan

Post navigation

Previous Post: Alice Secures $140 Million to Combat AI Threats
Next Post: CISA Red Team Uncovers Security Flaws in Critical Infrastructure

Related Posts

Grafana GitHub Breach from npm Attack Exposes Code Grafana GitHub Breach from npm Attack Exposes Code The Hacker News
New Vulnerabilities in Lantronix and Silex Serial-to-IP Converters New Vulnerabilities in Lantronix and Silex Serial-to-IP Converters The Hacker News
Chrome 0-Day, AI Hacking Tools, DDR5 Bit-Flips, npm Worm & More Chrome 0-Day, AI Hacking Tools, DDR5 Bit-Flips, npm Worm & More The Hacker News
New ClickFix Variant Exploits Network Drives New ClickFix Variant Exploits Network Drives The Hacker News
OpenClaw Enhances Security with VirusTotal Integration OpenClaw Enhances Security with VirusTotal Integration The Hacker News
Fastjson Vulnerability Exploited in Active Attacks Fastjson Vulnerability Exploited in Active Attacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical AnyDesk Linux Vulnerability Allows Remote Code Execution
  • Exploits Target AhsayCBS to Deploy Crypto Miners
  • CastleStealer Malware Expands with New Browser Bypass
  • FBI Nabs Suspect Linked to ShinyHunters Hack
  • Comprehensive AI Security Checklist Introduces 222 Tests

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical AnyDesk Linux Vulnerability Allows Remote Code Execution
  • Exploits Target AhsayCBS to Deploy Crypto Miners
  • CastleStealer Malware Expands with New Browser Bypass
  • FBI Nabs Suspect Linked to ShinyHunters Hack
  • Comprehensive AI Security Checklist Introduces 222 Tests

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark