Security1 distinct publisher3 min readPublished
SOCRadar says two previously unreported RATs pull their next-stage commands out of FTP greetings. It is a first in the wild, and noisier than the web dead drops it replaces.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The tell here is the protocol, not the payload. SOCRadar's own write-up undercuts the technique it documents: pulling commands from an FTP greeting is less stealthy than the web-based dead drop resolvers it substitutes for, because security controls are likely to treat an FTP connection to an unknown server as anomalous [5]. In an estate that does no legitimate FTP, that is one query against flow records, and the report names three control-plane hosts to seed the list [17].
So the choice reads as cost rather than craft. A banner is a text field on a box the operator already runs. The alternative sits in the second family: PINHOLE keeps its C2 details on Pinterest and SurveyMonkey and proxies the traffic through Cloudflare Workers [12], which buys reputation at the price of depending on somebody else's abuse desk.
Two details deserve more attention than the banner itself. E4del arrives as a Node.js RAT embedded in a digitally signed Electron application dressed up as Discord [9], which means the signature is carrying weight that the delivery chain never tries to earn. And the beaconing is tiered rather than fixed: inside the first 20 seconds of receiving a task it checks in every 200 milliseconds to 2 seconds, drops to 2 to 5 seconds after 20 to 40 idle seconds, and settles at 5 to 9 seconds past 40 [11]. At the fast end that is roughly 300 check-ins a minute against about 7 to 12 in the quiet state, a swing of some 25 to 45 times [16]. Periodicity heuristics tuned to a single sleep value will not see a consistent rhythm to lock onto, which pushes detection back onto the FTP leg and the WebDAV fetch.
That fetch is not new either. The same WebDAV-to-rundll32 pattern has been reported in a ClearFake campaign delivering WordlistLoader and Amatera Stealer behind ClickFix lures, per Microsoft and Gen Threat Labs [7]. The novelty is confined to where the address comes from.
PINHOLE's loader is the more serious engineering. Its banner at 209.99.185[.]38:21 held PowerShell that used the MSXML2.XMLHTTP COM object to pull a script, wrote it to %TEMP%u.cmd, ran it, then deleted it [13]. The wrapper presents itself as an update utility from Weston Computing Systems Ltd, a company that does not exist, and uses Halo's Gate to get past security software [14]. Six unpacking layers and an Early Bird APC injection into a suspended legitimate process protect a 119 KB x86-64 executable [15]. All of that scaffolding guards a payload smaller than a phone photo.
One caveat on the sourcing. The two reports supplied here are the same article from the same publisher, so every technical detail traces back to a single vendor report [18]. The only other party credited with seeing the method is MalwareHunterTeam, which flagged it early last month [4]. Treat the indicators as a hunting hypothesis rather than a confirmed inventory until a second party publishes on the same hosts.
Ranked by verification strength, evidence, and original report placement.
A new campaign uses FTP banners as dead drop resolvers to deliver two previously unreported remote access trojans tracked as E4del and PINHOLE.
An FTP banner is a welcome message or text string an FTP server sends to a client immediately on connection; SOCRadar says the mechanism allows malware stagers to fetch commands directly from the protocol's initial response.
PINHOLE's first-stage wrapper claims to be an update utility from a non-existent company named Weston Computing Systems Ltd, and the binary employs the Halo's Gate technique to bypass security software.
The payload is run via an Early Bird APC injection routine inside a legitimate suspended process, after six layers of unpacking that extract a 119 KB native x86-64 PE executable.
The development marks the first time this technique has been spotted in the wild.
The modus operandi was first highlighted by the MalwareHunterTeam early last month.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed single-vendor technical report, no independent confirmation
The technical substance is unusually concrete for a single-source story: three named FTP banner hosts, a specific staging URL and %TEMP% artefact, beacon interval tiers, a 119 KB x86-64 payload behind six unpack layers, and named evasion techniques. But every element traces to one SOCRadar report relayed by one outlet, with corroboration only for adjacent activity (MalwareHunterTeam on the technique, Microsoft and Gen Threat Labs on related ClearFake WebDAV delivery) rather than for E4del or PINHOLE themselves, and with no victimology or telemetry to size the activity.
Confirmed in the wild, scale unquantified
Adoption of the technique by attackers is confirmed rather than theoretical: two malware families, three banner-serving FTP hosts, a live staging domain, an operator-run stats panel and a related WebDAV-based ClearFake campaign reported by other vendors. What is entirely absent is scale, no victim counts, sectors, regions beyond Spanish-language lures, or figures from the attackers' own panel, so this reads as early, narrow deployment rather than widespread use.
Novelty framing modestly ahead of demonstrated impact
The framing leans on firsts, first in-the-wild use of the technique and two previously unreported families, while no impact evidence is offered: no victims, no scale, no dwell time. That tilts slightly overstated. It is only slightly, because the same article volunteers the strongest deflating fact, that FTP egress to unknown servers is likely to be flagged as anomalous, making this a noisier channel than the web dead drops it replaces, and because the underlying malware analysis is detailed rather than promotional.
Commercial threat-intel research amplified by aggregation
The source of all technical claims is a commercial threat-intelligence vendor publishing named-family research, which is a recognised marketing channel, and the naming of two previously unreported RATs plus a first-in-the-wild technique maximises that value. The relaying outlet operates on traffic from fast technical aggregation, and the cluster itself shows the same article distributed twice under a tracking URL. None of this is disclosed in the coverage, though the vendor is clearly named throughout.
Moderate: specific and internally consistent, but unverified beyond one vendor
Confidence is moderate. The account is internally consistent, technically specific and self-caveating, and the derived arithmetic on beacon rates and host counts follows directly from the reported figures. The limits are structural: no second publisher, no independent analysis of either family, no victim data, and no vendor-report primary document in the cluster, so a reader should treat the mechanism as credible and the significance as unproven.
security
FTP greeting banners are now a C2 channel, and they are carrying two new RATs2 distinct publishers
build
The malware asks a question and reads its orders off the doormat: PowerShell in FTP banners1 distinct publisher
security
PavinLoader: the lures keep changing, the MSBuild stage does not1 distinct publisher
security
GTA VI leak: extortion leverage moves from the regulator to the fanbase1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · August 25, 2026