Skip to content
Hackers Exploit FTP Banners to Distribute New Windows RATs E4del and PINHOLE

Hackers Exploit FTP Banners to Distribute New Windows RATs E4del and PINHOLE

First seen 21 Aug 2026, 13:47 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 22, 2026 at 12:20 UTC
  • •Threat actors are using FTP banners to deliver two new RATs, E4del and PINHOLE.
  • •The initial infection likely occurs through phishing, utilizing ZIP archives and LNK files.
  • •The malware employs stealth techniques, maintaining a minimal footprint on infected systems.

Threat actors are using FTP server banners to deliver two new remote access trojans (RATs), E4del and PINHOLE. This technique was first observed in July 2026 and involves using shortcut files (.LNK) to initiate an infection chain. The initial compromise likely occurs through phishing, with ZIP archives triggering the malware delivery. E4del is a Node.js-based RAT disguised as a Discord application, while PINHOLE utilizes SurveyMonkey questions for command and control. The malware exhibits stealthy behavior, maintaining a minimal footprint on infected systems. SOCRadar's research indicates that this method remains operational, with new infrastructure detected as of August 2026. The campaign is still in its early stages, with limited execution events reported for PINHOLE.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 47d ago How this analysis works

Timeline

2026-07-01
New attack technique observed
MalwareHunterTeam identified attacks using FTP banners for command delivery, marking a novel exploitation method.
BleepingComputer
2026-08-01
SOCRadar expands investigation
Researchers confirmed that the FTP banner exploitation technique remains active, with new infrastructure identified.
BleepingComputer
2026-08-21
BleepingComputer publishes findings
BleepingComputer reports on the ongoing use of FTP banners to deliver E4del and PINHOLE RATs, highlighting the campaign's early stage.
BleepingComputer

More articles in this cluster (5)

Following this threat?

Track E4del in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed