Build1 distinct publisher3 min readUpdated
SOCRadar says LNK files are pulling PowerShell out of FTP pre-login greetings to stage two RATs. The retrieval finishes before any login, so there is nothing for a transfer log to record.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
FTP's control channel opens with the server speaking first: a 220 line, sent before the client has offered a username [19][2]. SOCRadar's own response checklist makes the awkward part plain, asking analysts to preserve that 220 banner from packet capture if any exists [15]. Where it does not exist, the instruction that started the whole chain was never recorded anywhere. No credentials crossed the wire, no file moved, and the transfer accounting an FTP-aware proxy would keep stays empty [17].
The report's precondition list is honest about the shape of the environment this needs: outbound traffic to unknown FTP servers is permitted, PowerShell and multi-stage execution are not blocked, and traffic to legitimate web services and Cloudflare Workers is allowed [13]. Both halves of the chain get through, but they are not equally watched, and the guidance reflects that. Counting SOCRadar's detection cues and mitigations together gives eight items, and two of them mention FTP at all [18]. The other six point at process injection, Workers traffic, Alternate Data Stream storage, gateway filtering of ZIP and LNK, and the Pinterest-to-Workers correlation [11][12].
That distribution matters because of where the FTP hop sits. In the confirmation ladder SOCRadar publishes, the first connection to an unknown FTP server lands one tier below "initial execution confirmed", which is PowerShell and loader execution after the banner has been read [16]. Every other network indicator in the writeup, the workers.dev traffic, nokierojotiarmx.com, the /api/tsk and /api/fls paths, appears at or after C2 registration [10]. The unauthenticated FTP session is the only network event available before the loader runs [20]. It is also the one that looks least like an incident.
The second-stage tradecraft is the same idea repeated with better-reputed hosts. PINHOLE keeps its encrypted C2 settings in Pinterest pins and SurveyMonkey questions and reaches the C2 through Cloudflare Workers, which is three third-party services carrying addressing for one loader [7][21], before it starts ApplicationFrameHost.exe suspended and drops the final RAT in with Early Bird APC [8]. E4del takes the other route and simply looks like software you already trust, arriving as a signed Electron app dressed as Discord with a Node.js RAT behind it [5].
Two things in the report are not settled, and SOCRadar says so. The component named crypto32.node is described as privilege escalation, but researchers could not recover it to confirm what it does [6]. Initial delivery is described as likely phishing and explicitly unconfirmed [14]. The disk-side residue is more definite: %TEMP%\calc.exe, settings in an ADS, and an HKCU Load entry [9].
The practical asymmetry is that the host artifacts survive for responders while the network artifact does not. Browser-saved credentials, screen content, files and command output are all in the confirmed-theft tier [16], and the rotation work that follows is fixed regardless [15]. What is optional is whether anyone can say which server sent the 220 line.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
SOCRadar Threat Research Unit published a report titled "FTP Banners: The New Dead Drop Resolver Delivering Novel RATs", dated 2026-08-21, rated severity High, covering malware named E4del and PINHOLE on Windows.
According to SOCRadar, attackers embed PowerShell commands into the greeting messages (banners) returned by FTP servers before login, and deliver two types of RATs via LNK files.
The chain begins when a user opens an LNK file inside a ZIP archive; SOCRadar states little action is needed other than opening the shortcut inside the ZIP.
The LNK file connects to an FTP server and gets PowerShell commands from the pre-login greeting message, and the retrieved commands start the delivery chain for E4del or PINHOLE.
PINHOLE's multi-stage loader resolves encrypted C2 settings from Pinterest and SurveyMonkey, using Pinterest pins and SurveyMonkey questions, and connects to the C2 via Cloudflare Workers to get the next stage.
Network indicators listed include continuous traffic to Pinterest, SurveyMonkey, workers.dev and nokierojotiarmx.com, and HTTP paths including /api/health, /api/client, /api/tsk and /api/fls.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed but single-vendor and partly unverified
The technical account is specific and internally coherent: named execution chain, host artifacts, network indicators including a C2 domain and /api paths, an explicit injection technique, and a five-tier confirmation ladder. But everything traces to one vendor report relayed by one publisher, with no independent corroboration in the cluster; the privilege escalation module was never recovered, and the initial intrusion vector is explicitly unconfirmed. That caps evidentiary strength around the midpoint.
Early, narrowly observed campaign
Real-world observation exists but is small: activity confirmed from early July 2026 and only 11 PINHOLE script execution records at analysis time, with no victim count, sector, geography or estimate of how many FTP servers serve weaponised banners. That supports 'confirmed in the wild, limited scale' rather than widespread exploitation.
Novelty framing runs slightly ahead of the substance
The 'new dead drop resolver' framing and High severity rating lean on the FTP banner trick, yet the vendor concedes unknown FTP connections stand out more than typical web-based dead drops and are relatively easy to detect where outbound logs exist, only two of eight guidance items concern FTP at all, the privilege escalation claim is unverified, and observed volume is 11 script executions. The underlying tradecraft is real and the detection advice is usable, so the overstatement is modest rather than severe.
Vendor-authored research with commercial threat-intel interest
The originating material is self-published research from a commercial threat-intelligence vendor that also assigns its own severity rating and names two malware families, all of which supports its product positioning; the cluster item is an unaffiliated developer-platform relay that adds no independent verification. Incentive to emphasise novelty and severity is therefore material, though the report still discloses limiting facts such as the unrecovered module, the unconfirmed vector and the relative detectability of FTP dead drops.
Moderate: rich detail, no corroboration
Assessment rests on a single relayed vendor report. Technique detail, indicators and defender guidance are specific enough to act on, but scale, targeting and attribution are absent, two elements are self-described as unconfirmed, and no second source in the cluster can validate any of it.
security
FTP greeting banners are now a C2 channel, and they are carrying two new RATs2 distinct publishers
build
Prisma v7 stops seeding for you, and the pooled URL will not finish the job1 distinct publisher
build
Short Build Roots Do Not Fix MAX_PATH: Unreal Cook Failures Are a Windows Setting1 distinct publisher
build
Codex learns to click: the coding agent stops typing patches and starts operating the machine1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
dev.to
1 article · August 21, 2026