Executive Summary
In July 2026, threat actors developed a novel attack technique using FTP server banners as dead-drop resolvers to deliver two previously undocumented remote access trojans: E4del and PINHOLE. The campaign begins with phishing attacks distributing ZIP archives containing malicious LNK files that connect to compromised FTP servers to retrieve PowerShell commands embedded in server greeting banners. E4del masquerades as Discord using a digitally signed Electron application, while PINHOLE uses sophisticated evasion techniques including shellcode fluctuation and retrieval of C2 configurations from Pinterest and SurveyMonkey. SOCRadar researchers found this technique remained active through August 2026 with new infrastructure continuously deployed.
This incident highlights the evolution of living-off-the-land techniques where attackers abuse legitimate protocols and services to evade detection, representing a broader trend toward more sophisticated command and control methods that bypass traditional security controls.
Why This Matters Now
The abuse of FTP banners represents a concerning evolution in dead-drop resolver techniques, demonstrating how threat actors continue to innovate around legitimate protocols to evade detection and maintain persistent command and control capabilities.
Attack Path Analysis
Attackers initiated compromise through phishing campaigns delivering ZIP archives containing malicious LNK files that connected to FTP servers with embedded commands in banners. The malware established persistence by masquerading as legitimate applications like Discord, then maintained command and control through novel dead-drop resolvers including Pinterest pins and SurveyMonkey surveys. Two distinct RATs (E4del and PINHOLE) were deployed to enable remote access, credential harvesting, and data exfiltration capabilities across compromised endpoints.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Phishing campaign delivers ZIP archives containing malicious LNK shortcut files that trigger FTP connections to retrieve embedded commands from server banners
MITRE ATT&CK® Techniques
Spearphishing Attachment
Malicious File
Non-Standard Port
Asynchronous Procedure Call
Web Service
Screen Capture
Credentials from Web Browsers
Invalid Code Signature
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Software engineering techniques for secure development
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Penetration testing and vulnerability assessments
Control ID: 500.05
DORA – Identification and classification of ICT risk
Control ID: Article 8
CISA ZTMM 2.0 – Microsegmentation and traffic inspection
Control ID: Network Segmentation
NIS2 Directive – Cybersecurity measures
Control ID: Article 21
ISO 27001 – Controls against malware
Control ID: A.12.2.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
FTP-delivered RATs threaten credential theft and data exfiltration in environments requiring PCI compliance, particularly vulnerable through phishing attacks targeting financial operations.
Information Technology/IT
IT infrastructure faces elevated risk from Node.js-based E4del and PINHOLE RATs exploiting FTP banners for command delivery and lateral movement capabilities.
Health Care / Life Sciences
Healthcare organizations vulnerable to credential stealing malware through phishing, risking HIPAA compliance violations and patient data exposure via remote access trojans.
Government Administration
Government systems at risk from sophisticated RATs using novel FTP banner techniques for command control, threatening sensitive data and operational security.
Sources
- Hackers abuse FTP server banners to deliver new Windows malwarehttps://www.bleepingcomputer.com/news/security/hackers-abuse-ftp-server-banners-to-deliver-new-windows-malware/Verified
- FTP Banners: New Dead Drop Resolver for RATshttps://socradar.io/blog/ftp-banners-new-dead-drop-resolver-rats/Verified
- MalwareHunterTeam Twitter Observationhttps://x.com/malwrhunterteam/status/2077717345007542539Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain this multi-stage attack by limiting lateral movement scope and reducing blast radius through microsegmentation and egress controls. The attacker's ability to establish persistent C2 channels and expand access across cloud workloads would be significantly restricted.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial compromise may still occur through phishing, but CNSF visibility would likely detect anomalous FTP traffic patterns and limit the malware's ability to reach additional cloud resources beyond the initially compromised endpoint
Control: Zero Trust Segmentation
Mitigation: Privilege escalation attempts may succeed on the local endpoint, but zero trust segmentation would likely prevent the elevated privileges from accessing other workloads or sensitive cloud resources beyond the compromised system's assigned security perimeter
Control: East-West Traffic Security
Mitigation: Lateral movement attempts would likely be significantly constrained by east-west traffic inspection, preventing the RATs from accessing adjacent cloud workloads or expanding their foothold across the broader infrastructure environment
Control: Multicloud Visibility & Control
Mitigation: C2 communication channels would likely be detected and disrupted through comprehensive traffic analysis, limiting the attackers' ability to maintain persistent command and control over compromised cloud workloads across multiple environments
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely be constrained by egress security controls that monitor and restrict outbound data flows, limiting the volume and scope of sensitive information that could be successfully transmitted to external systems
Residual impact would likely be constrained to the initially compromised workload segment, with limited ability to affect broader cloud infrastructure or access sensitive data repositories due to microsegmentation boundaries and egress restrictions
Impact at a Glance
Affected Business Functions
- Corporate Information Security
- IT Infrastructure Operations
- Data Privacy and Protection
- Business Continuity Management
Estimated downtime: 3 days
Estimated loss: $75,000
Potential exposure includes browser-stored credentials, screenshots of desktop activities, file system enumeration, and command execution capabilities allowing access to sensitive corporate data and intellectual property
Recommended Actions
Key Takeaways & Next Steps
- • Deploy Cloud Firewall (ACF) with URL filtering and egress controls to block unauthorized FTP connections and novel C2 channels to Pinterest/SurveyMonkey
- • Implement Inline IPS (Suricata) to detect and block malicious payload delivery patterns and exploit traffic from compromised endpoints
- • Enable Egress Security & Policy Enforcement to prevent unauthorized data exfiltration and restrict outbound connections to unknown FTP servers
- • Activate Threat Detection & Anomaly Response capabilities to identify suspicious FTP banner abuse and remote access tool deployment patterns
- • Establish Multicloud Visibility & Control to monitor for anomalous automation patterns and repeated malformed requests indicative of RAT activity



