Find notable cyber news and cases, enriched with sources, timelines, and signals.

E4del and PINHOLE Windows RAT activity via FTP-banner dead-drop resolvers

Malware Activity
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

New Windows RAT activity has been identified using FTP banners as dead-drop resolvers to deliver E4del and PINHOLE, increasing risk from remote command execution, screenshot capture, and credential theft. The activity has been operational since early July 2026 and remained active into August 2026, showing that the delivery method is still in use. The infection chain relies on .LNK-based execution and likely phishing to start the compromise. The two malware families use different C2 and execution paths, but both aim to establish durable remote access on victim systems.

Related Happenings

FTP-banner dead-drop resolver malware delivery campaign

Campaign
H score39 First: 21.08.2026 14:00 Last: 21.08.2026 14:00 Sources 1

How related: "By utilizing FOFA searches, we determined that this technique has been weaponized since early July 2026 and remains operational, with new infrastructure observed as recently as August 2026."

About this happening: A campaign is using FTP banners as dead-drop resolvers to deliver E4del and PINHOLE, creating a new command-delivery path that can bypass standard web-service moni...

Konni blockchain developer targeting campaign with AI-generated PowerShell malware

Campaign
H score33 First: 24.01.2026 17:23 Last: 24.01.2026 17:23 Sources 1

About this happening: Konni (Opal Sleet, TA406) is running an active campaign that uses AI-generated PowerShell malware to target developers and engineers in the blockchain sector, with...

Timeline

  1. 21.08.2026 14:00 2 articles · 1h ago

    FTP banners deliver E4del and PINHOLE in a Windows malware campaign

    Initial Disclosure

    Threat actors abuse FTP server banners as dead-drop resolvers to deliver two previously undocumented Windows RATs, E4del and PINHOLE, against affected Windows systems. The infection chain starts with a ZIP archive that triggers LNK-based execution, likely through phishing, and both routes retrieve a PowerShell script from FTP banners. E4del is a Node.js-based RAT packaged inside a digitally signed Electron application masquerading as Discord, while PINHOLE pulls C2 configuration from Pinterest pins and SurveyMonkey survey questions.

    Show sources