Executive Summary

In July 2026, threat actors developed a novel attack technique using FTP server banners as dead-drop resolvers to deliver two previously undocumented remote access trojans: E4del and PINHOLE. The campaign begins with phishing attacks distributing ZIP archives containing malicious LNK files that connect to compromised FTP servers to retrieve PowerShell commands embedded in server greeting banners. E4del masquerades as Discord using a digitally signed Electron application, while PINHOLE uses sophisticated evasion techniques including shellcode fluctuation and retrieval of C2 configurations from Pinterest and SurveyMonkey. SOCRadar researchers found this technique remained active through August 2026 with new infrastructure continuously deployed.

This incident highlights the evolution of living-off-the-land techniques where attackers abuse legitimate protocols and services to evade detection, representing a broader trend toward more sophisticated command and control methods that bypass traditional security controls.

Why This Matters Now

The abuse of FTP banners represents a concerning evolution in dead-drop resolver techniques, demonstrating how threat actors continue to innovate around legitimate protocols to evade detection and maintain persistent command and control capabilities.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Attackers embed malicious PowerShell commands in FTP server greeting banners, which are automatically retrieved when compromised systems connect to the server, creating a novel dead-drop resolver method.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely constrain this multi-stage attack by limiting lateral movement scope and reducing blast radius through microsegmentation and egress controls. The attacker's ability to establish persistent C2 channels and expand access across cloud workloads would be significantly restricted.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Initial compromise may still occur through phishing, but CNSF visibility would likely detect anomalous FTP traffic patterns and limit the malware's ability to reach additional cloud resources beyond the initially compromised endpoint

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Privilege escalation attempts may succeed on the local endpoint, but zero trust segmentation would likely prevent the elevated privileges from accessing other workloads or sensitive cloud resources beyond the compromised system's assigned security perimeter

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement attempts would likely be significantly constrained by east-west traffic inspection, preventing the RATs from accessing adjacent cloud workloads or expanding their foothold across the broader infrastructure environment

Command & Control

Control: Multicloud Visibility & Control

Mitigation: C2 communication channels would likely be detected and disrupted through comprehensive traffic analysis, limiting the attackers' ability to maintain persistent command and control over compromised cloud workloads across multiple environments

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration attempts would likely be constrained by egress security controls that monitor and restrict outbound data flows, limiting the volume and scope of sensitive information that could be successfully transmitted to external systems

Impact (Mitigations)

Residual impact would likely be constrained to the initially compromised workload segment, with limited ability to affect broader cloud infrastructure or access sensitive data repositories due to microsegmentation boundaries and egress restrictions

Impact at a Glance

Affected Business Functions

  • Corporate Information Security
  • IT Infrastructure Operations
  • Data Privacy and Protection
  • Business Continuity Management
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $75,000

Data Exposure

Potential exposure includes browser-stored credentials, screenshots of desktop activities, file system enumeration, and command execution capabilities allowing access to sensitive corporate data and intellectual property

Recommended Actions

  • Deploy Cloud Firewall (ACF) with URL filtering and egress controls to block unauthorized FTP connections and novel C2 channels to Pinterest/SurveyMonkey
  • Implement Inline IPS (Suricata) to detect and block malicious payload delivery patterns and exploit traffic from compromised endpoints
  • Enable Egress Security & Policy Enforcement to prevent unauthorized data exfiltration and restrict outbound connections to unknown FTP servers
  • Activate Threat Detection & Anomaly Response capabilities to identify suspicious FTP banner abuse and remote access tool deployment patterns
  • Establish Multicloud Visibility & Control to monitor for anomalous automation patterns and repeated malformed requests indicative of RAT activity

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image