Hackers Exploit FTP Banners to Distribute New Windows RATs E4del and PINHOLE

Hackers Exploit FTP Banners to Distribute New Windows RATs E4del and PINHOLE

First seen 21 Aug 2026, 13:47 UTC Bleepingcomputer 100% similarity 51.9

Article Content

Browse articles
ThreatCluster

Threat actors are using FTP server banners to deliver two new remote access trojans (RATs), E4del and PINHOLE. This technique was first observed in July 2026 and involves using shortcut files (.LNK) to initiate an infection chain. The initial compromise likely occurs through phishing, with ZIP archives triggering the malware delivery. E4del is a Node.js-based RAT disguised as a Discord application, while PINHOLE utilizes SurveyMonkey questions for command and control. The malware exhibits stealthy behavior, maintaining a minimal footprint on infected systems. SOCRadar's research indicates that this method remains operational, with new infrastructure detected as of August 2026. The campaign is still in its early stages, with limited execution events reported for PINHOLE.

Key Points: • Threat actors are using FTP banners to deliver two new RATs, E4del and PINHOLE. • The initial infection likely occurs through phishing, utilizing ZIP archives and LNK files. • The malware employs stealth techniques, maintaining a minimal footprint on infected systems.

ThreatCluster AI How this analysis works

Timeline

2026-07-01
New attack technique observed
MalwareHunterTeam identified attacks using FTP banners for command delivery, marking a novel exploitation method.
BleepingComputer
2026-08-01
SOCRadar expands investigation
Researchers confirmed that the FTP banner exploitation technique remains active, with new infrastructure identified.
BleepingComputer
2026-08-21
BleepingComputer publishes findings
BleepingComputer reports on the ongoing use of FTP banners to deliver E4del and PINHOLE RATs, highlighting the campaign's early stage.
BleepingComputer

Community

Browse all →

Tracked Entities in This Story