Security1 distinct publisher3 min readUpdated
SOCRadar says attackers have used FTP server login banners as dead-drop resolvers since early July 2026 to stage two undocumented remote access trojans, E4del and PINHOLE.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
A malware stager is now reading its instructions out of the text an FTP server sends before anyone logs in, and that text is being used to deliver two previously undocumented remote access trojans called E4del and PINHOLE [1]. FTP banners are just greeting strings returned to a connecting host prior to authentication, which means the malicious content arrives inside a step that looks like protocol politeness rather than a download [3][4].
MalwareHunterTeam saw the technique in July in an attack that paired shortcut files with FTP banners used as dead-drop resolvers to fetch commands [2]. Researchers at SOCRadar, who ran into the same trick during an investigation and then went hunting, say the chain begins with a ZIP archive that triggers an LNK-based infection, with initial compromise likely by phishing [5][7]. Both infection routes end the same way: a PowerShell script pulled out of an FTP banner [8]. Using FOFA searches, SOCRadar states the technique "has been weaponized since early July 2026 and remains operational, with new infrastructure observed as recently as August 2026" [6], meaning the infrastructure has stayed alive across at least two calendar months [20].
E4del is a Node.js RAT wrapped in a digitally signed Electron application that pretends to be Discord [9]. It runs commands through persistent or temporary shells, takes screenshots, streams the desktop over WebSockets, and downloads and executes further payloads [10]. SOCRadar also references a Node.js module named crypto32.node that attempts privilege escalation but which the researchers could not obtain for analysis, so that part of the capability set is asserted rather than examined [11].
PINHOLE is the more careful of the two. It takes its C2 configuration from Pinterest pins and SurveyMonkey survey questions, which SOCRadar frames as resilience against takedowns [12]. On the host it keeps a single 4KB section of the payload in memory at a time through shellcode fluctuation, then injects the final assembly into a suspended ApplicationFrameHost.exe using Early Bird APC injection [13]. It supports 14 commands, including file enumeration, upload and download, command execution, process management, screenshots, and a module for lifting browser-stored credentials [14].
Scale is small so far. At the time of analysis the PINHOLE script had logged only 11 execution events, which SOCRadar reads as an early-stage campaign [15].
The honest caveat comes from the researchers themselves: they call FTP banners a novel alternative but less stealthy than web-based dead drops on X, GitHub or YouTube, because those services provide cover through high-volume expected traffic while FTP connections to unknown servers stand out [16][17]. That holds only for networks that actually record outbound FTP and retain the greeting string. Netflow that notes a session to port 21 and nothing else will not show you the command, and blocklists built around web dead drops will not fire at all.
What to watch: whether the technique migrates into ClickFix-style lures, which SOCRadar says it could be adapted for easily [18], and whether PINHOLE's execution counter climbs past 11 [15]. SOCRadar's report includes indicators for both the infrastructure and infected hosts [19].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE.
MalwareHunterTeam observed the technique in July in an attack that used shortcut files (.LNK) and FTP server banners as dead-drop resolvers to retrieve commands.
FTP banners are text strings the server uses as a greeting message for connecting hosts before they log in.
By embedding commands in the initial response sent when a compromised system connects to an FTP server, a malware stager can receive instructions from a remote server.
After discovering FTP banners delivering malicious commands during an investigation, researchers at threat intelligence platform SOCRadar expanded their hunt and found the technique remains in use.
SOCRadar: "By utilizing FOFA searches, we determined that this technique has been weaponized since early July 2026 and remains operational, with new infrastructure observed as recently as August 2026."
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed single-vendor report, no independent corroboration
Technical specificity is high and falsifiable: named malware families, a described ZIP/LNK/PowerShell chain, concrete evasion mechanics, a stated hunting method, and published IOCs. But every claim traces to one threat-intelligence vendor relayed by one publisher, no second researcher or CERT confirms it, no IOCs are reproduced in the article, and one capability (crypto32.node privilege escalation) could not be retrieved for analysis.
Early-stage attacker adoption, narrow observed footprint
Attacker uptake is real and persistent rather than theoretical: an independent initial sighting by MalwareHunterTeam, weaponization since early July 2026, and new infrastructure into August 2026. Scale remains small, with only 11 recorded PINHOLE executions, no victim counts, sectors or geographies disclosed, and the vendor describing the campaign as early-stage.
Framing runs slightly ahead of measured scale
The 'FTP banners are now a C2 channel' framing with two named new RATs implies broader significance than a disclosed footprint of 11 executions supports, and the ClickFix adaptation is speculation rather than observation. The overstatement is modest because the same reporting carries the vendor's deflating caveats about reduced stealth and early-stage scale.
Vendor research promoted via exclusive plus appended report ad
Findings originate with SOCRadar, a commercial threat-intelligence platform, and were shared exclusively with a security trade publication, an arrangement that rewards novelty framing. The article body also closes with promotional copy for a separate commercial security report, unseparated from the reporting. No publisher-vendor financial relationship is disclosed either way in the supplied material.
Plausible and specific, but single-sourced and small-scale
The mechanism is technically coherent, partly corroborated by an independent researcher's initial sighting, and accompanied by IOCs, supporting the core claim that the technique exists and is in active use. Confidence is held down by a single publisher and single vendor, unverified components, absent victimology, and a footprint too small to judge trajectory.
build
The 46GB Leak Your RSS Alert Cannot See: macOS Compressed Memory Breaks Threshold Monitoring1 distinct publisher
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
build
A GAN beauty filter is a device budget allocation, not a feature toggle1 distinct publisher
build
Every viewer hits your HLS key endpoint in the same second, and almost nobody tests it1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 21, 2026