FTP-banner dead-drop resolver malware delivery campaign
Campaign
Summary
Hide ▲
Show ▼
A campaign is using FTP banners as dead-drop resolvers to deliver E4del and PINHOLE, creating a new command-delivery path that can bypass standard web-service monitoring. The operation has been weaponized since early July 2026 and was still active with new infrastructure seen in August 2026. It starts with ZIP archives that trigger a .LNK infection chain, and researchers assess phishing as the likely initial access route. The payloads provide remote access, screen capture, file transfer, and credential-theft capabilities.
Related Happenings
E4del and PINHOLE Windows RAT activity via FTP-banner dead-drop resolvers
Malware Activity
H score29
First: 21.08.2026 14:00
Last: 21.08.2026 14:00
Sources 1
How related:
The infection chain delivers two remote access trojans (RATs) named E4del and PINHOLE via two distinct infection routes, both retrieving a PowerShell script from FTP banners.
About this happening:
New Windows RAT activity has been identified using FTP banners as dead-drop resolvers to deliver E4del and PINHOLE, increasing risk from remote command execution,...
E4del and PINHOLE Windows RAT activity via FTP-banner dead-drop resolvers
Malware ActivityHow related: The infection chain delivers two remote access trojans (RATs) named E4del and PINHOLE via two distinct infection routes, both retrieving a PowerShell script from FTP banners.
About this happening: New Windows RAT activity has been identified using FTP banners as dead-drop resolvers to deliver E4del and PINHOLE, increasing risk from remote command execution,...
Gremlin stealer modular toolkit evolution
Malware Activity
H score21
First: 15.05.2026 17:19
Last: 15.05.2026 17:19
Sources 1
About this happening:
The Gremlin stealer malware has expanded into a modular toolkit with session-hijacking and crypto clipping capabilities, raising the risk of credential theft and a...
Gremlin stealer modular toolkit evolution
Malware ActivityAbout this happening: The Gremlin stealer malware has expanded into a modular toolkit with session-hijacking and crypto clipping capabilities, raising the risk of credential theft and a...
Timeline
-
21.08.2026 14:00 2 articles · 1h ago
Threat actors use FTP banners to deliver E4del and PINHOLE
Initial DisclosureThreat actors are abusing FTP server banners as dead-drop resolvers to hide commands that deliver two previously undocumented Windows RATs, E4del and PINHOLE. SOCRadar says the campaign was weaponized since early July 2026, remained operational in August 2026, and used a ZIP archive that triggers an LNK-based infection chain, likely through phishing, with both infection routes retrieving a PowerShell script from FTP banners. E4del is packaged in a digitally signed Electron application that masquerades as Discord, while PINHOLE pulls C2 configuration from Pinterest pins and SurveyMonkey survey questions.
Show sources
- Hackers abuse FTP server banners to deliver new Windows malware — www.bleepingcomputer.com — 21.08.2026 14:00
- Hackers abuse FTP server banners to deliver new Windows malware — www.bleepingcomputer.com — 21.08.2026 14:00