Executive Summary
Cybersecurity researchers have identified a sophisticated new campaign employing FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) named E4del and PINHOLE. The threat actors behind this campaign are exploiting legitimate FTP services to establish command-and-control infrastructure while blending seamlessly with regular network traffic. This novel technique allows attackers to maintain persistent access to compromised systems while evading traditional detection methods that focus on more conventional C2 communication channels. The campaign demonstrates advanced operational security awareness and represents a significant evolution in how threat actors establish and maintain covert communication channels.
This incident highlights the growing trend of threat actors exploiting legitimate services and protocols for malicious purposes, making detection increasingly challenging for traditional security tools. As organizations continue to expand their digital infrastructure, the abuse of standard network services like FTP for covert communication channels represents a critical blind spot in many security monitoring strategies.
Why This Matters Now
The emergence of FTP banner abuse for C2 communication represents a new frontier in stealth tactics that can bypass traditional network monitoring, requiring organizations to reassess their detection capabilities for legitimate service abuse.
Attack Path Analysis
E4del and PINHOLE RATs employ FTP banners as dead drop resolvers to establish covert command and control channels. The attack begins with initial compromise through delivery of the RAT payload, followed by establishing persistence and privilege escalation on the compromised system. The malware then uses FTP banner manipulation for command and control communication, potentially enabling data exfiltration and maintaining long-term access for reconnaissance and data theft operations.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
E4del and PINHOLE RAT payloads delivered to target systems through unspecified delivery mechanism, establishing initial foothold
MITRE ATT&CK® Techniques
Application Layer Protocol: File Transfer Protocols
Proxy: Multi-hop Proxy
Web Service
Remote Access Software
Fallback Channels
Data Encoding: Standard Encoding
Process Injection
Obfuscated Files or Information
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST Cybersecurity Framework 2.0 – Networks and network services are monitored
Control ID: DE.CM-1
CISA Zero Trust Maturity Model 2.0 – Encrypted Traffic Inspection
Control ID: Network Security - Advanced
NYDFS 23 NYCRR 500 – Penetration Testing and Vulnerability Assessments
Control ID: 500.15
Digital Operational Resilience Act (DORA) – Identification and Classification of ICT Risk
Control ID: Article 8
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001:2022 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
FTP-based RATs threaten encrypted traffic and egress security, requiring enhanced east-west segmentation and anomaly detection for regulatory compliance.
Health Care / Life Sciences
Remote access trojans exploit network visibility gaps, demanding zero trust segmentation and multicloud controls for HIPAA data protection.
Information Technology/IT
E4del and PINHOLE RATs leverage command-and-control infrastructure, necessitating threat detection capabilities and kubernetes security for client environments.
Government Administration
Dead drop resolver techniques bypass traditional security, requiring inline IPS and cloud native security fabric for critical infrastructure protection.
Sources
- E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commandshttps://thehackernews.com/2026/08/e4del-and-pinhole-rats-turn-ftp-banners.htmlVerified
- MITRE ATT&CK - Remote Access Trojanhttps://attack.mitre.org/techniques/T1219/Verified
- CISA - Command and Control Techniqueshttps://www.cisa.gov/news-events/cybersecurity-advisoriesVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would constrain E4del and PINHOLE RAT operations by reducing lateral movement scope and limiting covert FTP-based communication channels. The segmented architecture would likely contain the blast radius and restrict attacker reach across cloud environments.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Post-compromise workload isolation would likely limit the attacker's ability to discover and access adjacent cloud resources beyond the initially compromised system
Control: Zero Trust Segmentation
Mitigation: Identity-aware access controls would likely restrict the RAT's ability to leverage elevated privileges for accessing segmented network zones or privileged service accounts
Control: East-West Traffic Security
Mitigation: Microsegmentation policies would likely block unauthorized lateral communication attempts and reduce the attacker's ability to enumerate or access additional cloud workloads
Control: Multicloud Visibility & Control
Mitigation: Enhanced traffic inspection would likely detect and alert on anomalous FTP banner manipulation patterns that deviate from baseline communication behaviors
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely restrict unauthorized outbound data flows and limit the RAT's ability to exfiltrate sensitive information through covert channels
Residual impact would likely be constrained to the initially compromised workload segment with reduced ability to access sensitive data across the broader cloud infrastructure
Impact at a Glance
Affected Business Functions
- Network Security Operations
- Remote Access Management
- File Transfer Services
- Command and Control Monitoring
Estimated downtime: 3 days
Estimated loss: $50,000
Potential unauthorized remote access to corporate networks, file systems, and internal communications through covert FTP banner command channels
Recommended Actions
Key Takeaways & Next Steps
- • Implement Egress Security & Policy Enforcement to block unauthorized outbound FTP traffic and prevent covert C2 channels through FQDN filtering
- • Deploy Multicloud Visibility & Control to detect anomalous FTP banner interactions and suspicious automation patterns across hybrid environments
- • Enable Threat Detection & Anomaly Response capabilities to baseline normal FTP usage and alert on remote access tool behaviors
- • Establish Zero Trust Segmentation with least privilege access to limit RAT lateral movement and contain compromise impact
- • Configure Inline IPS (Suricata) to identify and block known RAT signatures and malicious payload delivery attempts



