Skip to content

Security2 publishersIndependently confirmed3 min readPublished

FTP greeting banners are now a C2 channel, and they are carrying two new RATs

SOCRadar says attackers have used FTP server login banners as dead-drop resolvers since early July 2026 to stage two undocumented remote access trojans, E4del and PINHOLE.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying FTP greeting banners are now a C2 channel, and they are carrying two new RATs
Generated illustration

What happened

  • Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE.
  • MalwareHunterTeam observed the technique in July in an attack that used shortcut files (.LNK) and FTP server banners as dead-drop resolvers to retrieve commands.
  • FTP banners are text strings the server uses as a greeting message for connecting hosts before they log in.
  • By embedding commands in the initial response sent when a compromised system connects to an FTP server, a malware stager can receive instructions from a remote server.
  • After discovering FTP banners delivering malicious commands during an investigation, researchers at threat intelligence platform SOCRadar expanded their hunt and found the technique remains in use.

Compiled by The WatchSomething wrong?How this is made

Why it matters

A malware stager is now reading its instructions out of the text an FTP server sends before anyone logs in, and that text is being used to deliver two previously undocumented remote access trojans called E4del and PINHOLE [1]. FTP banners are just greeting strings returned to a connecting host prior to authentication, which means the malicious content arrives inside a step that looks like protocol politeness rather than a download [12][13].

MalwareHunterTeam saw the technique in July in an attack that paired shortcut files with FTP banners used as dead-drop resolvers to fetch commands [2]. Researchers at SOCRadar, who ran into the same trick during an investigation and then went hunting, say the chain begins with a ZIP archive that triggers an LNK-based infection, with initial compromise likely by phishing [14][3]. Both infection routes end the same way: a PowerShell script pulled out of an FTP banner [4]. Using FOFA searches, SOCRadar states the technique "has been weaponized since early July 2026 and remains operational, with new infrastructure observed as recently as August 2026" [15], meaning the infrastructure has stayed alive across at least two calendar months [18].

E4del is a Node.js RAT wrapped in a digitally signed Electron application that pretends to be Discord [5]. It runs commands through persistent or temporary shells, takes screenshots, streams the desktop over WebSockets, and downloads and executes further payloads [6]. SOCRadar also references a Node.js module named crypto32.node that attempts privilege escalation but which the researchers could not obtain for analysis, so that part of the capability set is asserted rather than examined [20].

PINHOLE is the more careful of the two. It takes its C2 configuration from Pinterest pins and SurveyMonkey survey questions, which SOCRadar frames as resilience against takedowns [7]. On the host it keeps a single 4KB section of the payload in memory at a time through shellcode fluctuation, then injects the final assembly into a suspended ApplicationFrameHost.exe using Early Bird APC injection [8]. It supports 14 commands, including file enumeration, upload and download, command execution, process management, screenshots, and a module for lifting browser-stored credentials [9].

Scale is small so far. At the time of analysis the PINHOLE script had logged only 11 execution events, which SOCRadar reads as an early-stage campaign [16].

The honest caveat comes from the researchers themselves: they call FTP banners a novel alternative but less stealthy than web-based dead drops on X, GitHub or YouTube, because those services provide cover through high-volume expected traffic while FTP connections to unknown servers stand out [10][11]. That holds only for networks that actually record outbound FTP and retain the greeting string. Netflow that notes a session to port 21 and nothing else will not show you the command, and blocklists built around web dead drops will not fire at all.

What to watch: whether the technique migrates into ClickFix-style lures, which SOCRadar says it could be adapted for easily [19], and whether PINHOLE's execution counter climbs past 11 [16]. SOCRadar's report includes indicators for both the infrastructure and infected hosts [17].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories