Find notable cyber news and cases, enriched with sources, timelines, and signals.

FTP-banner dead-drop resolver malware delivery campaign

Campaign
First reported
Last updated
Happening score
H score 39
1 unique sources, 1 articles

Summary

Hide ▲

A campaign is using FTP banners as dead-drop resolvers to deliver E4del and PINHOLE, creating a new command-delivery path that can bypass standard web-service monitoring. The operation has been weaponized since early July 2026 and was still active with new infrastructure seen in August 2026. It starts with ZIP archives that trigger a .LNK infection chain, and researchers assess phishing as the likely initial access route. The payloads provide remote access, screen capture, file transfer, and credential-theft capabilities.

Related Happenings

E4del and PINHOLE Windows RAT activity via FTP-banner dead-drop resolvers

Malware Activity
H score29 First: 21.08.2026 14:00 Last: 21.08.2026 14:00 Sources 1

How related: The infection chain delivers two remote access trojans (RATs) named E4del and PINHOLE via two distinct infection routes, both retrieving a PowerShell script from FTP banners.

About this happening: New Windows RAT activity has been identified using FTP banners as dead-drop resolvers to deliver E4del and PINHOLE, increasing risk from remote command execution,...

Gremlin stealer modular toolkit evolution

Malware Activity
H score21 First: 15.05.2026 17:19 Last: 15.05.2026 17:19 Sources 1

About this happening: The Gremlin stealer malware has expanded into a modular toolkit with session-hijacking and crypto clipping capabilities, raising the risk of credential theft and a...

Timeline

  1. 21.08.2026 14:00 2 articles · 1h ago

    Threat actors use FTP banners to deliver E4del and PINHOLE

    Initial Disclosure

    Threat actors are abusing FTP server banners as dead-drop resolvers to hide commands that deliver two previously undocumented Windows RATs, E4del and PINHOLE. SOCRadar says the campaign was weaponized since early July 2026, remained operational in August 2026, and used a ZIP archive that triggers an LNK-based infection chain, likely through phishing, with both infection routes retrieving a PowerShell script from FTP banners. E4del is packaged in a digitally signed Electron application that masquerades as Discord, while PINHOLE pulls C2 configuration from Pinterest pins and SurveyMonkey survey questions.

    Show sources