Bleepingcomputer
Hackers Exploit FTP Banners to Distribute New Windows RATs E4del and PINHOLE
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Article Content
Threat actors are using FTP server banners to deliver two new remote access trojans (RATs), E4del and PINHOLE. This technique was first observed in July 2026 and involves using shortcut files (.LNK) to initiate an infection chain. The initial compromise likely occurs through phishing, with ZIP archives triggering the malware delivery. E4del is a Node.js-based RAT disguised as a Discord application, while PINHOLE utilizes SurveyMonkey questions for command and control. The malware exhibits stealthy behavior, maintaining a minimal footprint on infected systems. SOCRadar's research indicates that this method remains operational, with new infrastructure detected as of August 2026. The campaign is still in its early stages, with limited execution events reported for PINHOLE.
Key Points: • Threat actors are using FTP banners to deliver two new RATs, E4del and PINHOLE. • The initial infection likely occurs through phishing, utilizing ZIP archives and LNK files. • The malware employs stealth techniques, maintaining a minimal footprint on infected systems.