Bleepingcomputer Hackers Exploit FTP Banners to Distribute New Windows RATs E4del and PINHOLE
Article Content
- •Threat actors are using FTP banners to deliver two new RATs, E4del and PINHOLE.
- •The initial infection likely occurs through phishing, utilizing ZIP archives and LNK files.
- •The malware employs stealth techniques, maintaining a minimal footprint on infected systems.
Threat actors are using FTP server banners to deliver two new remote access trojans (RATs), E4del and PINHOLE. This technique was first observed in July 2026 and involves using shortcut files (.LNK) to initiate an infection chain. The initial compromise likely occurs through phishing, with ZIP archives triggering the malware delivery. E4del is a Node.js-based RAT disguised as a Discord application, while PINHOLE utilizes SurveyMonkey questions for command and control. The malware exhibits stealthy behavior, maintaining a minimal footprint on infected systems. SOCRadar's research indicates that this method remains operational, with new infrastructure detected as of August 2026. The campaign is still in its early stages, with limited execution events reported for PINHOLE.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track E4del in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…