SendTech Times
News
MARKET SIGNAL:

FTP Banner Dead Drops Deliver E4del And PINHOLE RAT Commands

Newsroom brief

Two newly documented RATs, E4del and PINHOLE, use FTP server banners as dead-drop command sources, with SOCRadar tracing chains that involve WebDAV, PowerShell, Cloudflare Workers and injection techniques.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: The Hacker News
FTP Banner Dead Drops Deliver E4del And PINHOLE RAT Commands
Image source: The Hacker News

FTP server banners are being used as command-delivery points for two previously undocumented remote access trojans, The Hacker News reported, giving defenders a new malware-delivery pattern to watch outside the usual web-based dead-drop channels.

Security researchers tied the activity to E4del and PINHOLE, two RAT families that retrieve commands from text strings returned by FTP servers when a client connects.

SOCRadar identified the technique as a dead drop resolver method and said MalwareHunterTeam first highlighted the approach early last month.

The E4del chain starts with Spanish-language voucher lures that persuade users to run a Windows Shortcut file.

The shortcut retrieves a command from an FTP banner, reaches a WebDAV server and uses rundll32.exe with conhost to execute a downloaded DLL export.

A separate FTP sequence at 157.254.194[.]31:21 and 167.148.41[.]164:21 leads to PowerShell activity that downloads, extracts and runs a ZIP-hosted binary.

E4del is built as a Node.js RAT embedded inside a digitally signed Electron application posing as Discord.

Its functions include persistence, system fingerprinting, encrypted command-and-control communication, interactive reverse shell access, screenshots, live desktop streaming, file download and additional payload delivery.

SOCRadar's technical report gives the malware a three-state beaconing model.

E4del checks in rapidly during the first 20 seconds after receiving a task, slows to a two-to-five-second interval between 20 and 40 seconds, and then moves to a five-to-nine-second interval after 40 seconds without new commands.

PINHOLE uses the same FTP-banner idea but adds higher-reputation services and Cloudflare Workers into the resolution path.

A banner at 209.99.185[.]38:21 contains PowerShell commands that retrieve a secondary script from a Cloudflare-linked domain, save it under the temporary directory, execute it and delete it.

The payload then moves through a wrapper presented as an update utility from a non-existent Weston Computing Systems Ltd.

The PINHOLE loader uses the Halo's Gate technique before handing the final executable to an Early Bird APC Injection routine inside a suspended legitimate process.

The source described six unpacking layers before the 119 KB native x86-64 payload appears, a sequence designed to complicate endpoint detection.

Once installed, PINHOLE can poll for commands over HTTP GET and POST, upload or download files, execute payloads, run PowerShell commands, enumerate directories and processes, take screenshots, terminate processes by PID and initialize a PowerShell session through anonymous pipes.

Researchers also found a dedicated FTP Stats Panel at 69.48.228[.]126:5000 that tracked script executions, total connections and unique active or blocked IP addresses.

The panel showed only 11 execution events at the time of analysis, leaving the campaign at an early stage rather than a broadly measured outbreak.

FTP-banner abuse is also less stealthy than traditional web dead drops because unusual FTP connections can stand out in monitored environments, but the technique gives attackers another place to hide first-stage instructions before defenders inspect the full payload chain.

Share this article
inXf

Related articles

More
Hostile SIM Research Exposes Phones And EV Chargers To Command Attacks
Cybersecurity

Hostile SIM Research Exposes Phones And EV Chargers To Command Attacks

University of Birmingham and Fuzzware researchers used CATana to show how malicious SIM cards can issue modem commands against phones, EV chargers and industrial equipment.

TrueConf Server Flaws Expose Client Installers To Backdoors
Cybersecurity

TrueConf Server Flaws Expose Client Installers To Backdoors

BleepingComputer reported that unpatched TrueConf servers are being abused to deliver backdoored client installers, with Kaspersky linking the activity to Head Mare and fixed server branches now available.

Philippine Cyber Teams Take DMW and DOLE Sites Offline After Intrusions
Cybersecurity

Philippine Cyber Teams Take DMW and DOLE Sites Offline After Intrusions

The DICT response covered unauthorized access at the migrant workers department, a defaced labor department page and a false-positive ransomware alert at the ports authority.

macOS Screen Sharing Flaw Gets Critical Rating After Root Compromises
Cybersecurity

macOS Screen Sharing Flaw Gets Critical Rating After Root Compromises

CVE-2026-65400 in macOS Screen Sharing was raised to a 9.8 critical score after Dutch officials documented exposed Macs being rooted and used for Monero mining.

Microsoft Patch Batch Puts Exploited Windows Driver First
Cybersecurity

Microsoft Patch Batch Puts Exploited Windows Driver First

The Hacker News reported that Microsoft’s August security release covers 398 CVEs, led by an actively exploited Windows afd.sys flaw and followed by four unauthenticated server RCE issues rated 9.8.

EU Cyber Resilience Act Puts 24-Hour Clock On Software Supply Chains
Cybersecurity

EU Cyber Resilience Act Puts 24-Hour Clock On Software Supply Chains

The European Commission lists 11 September 2026 as the start of Cyber Resilience Act reporting duties and 11 December 2027 for its main product-security obligations. Manufacturers face distinct reporting and engineering deadlines.

Metabase Zero-Day Forces Patch And Breach Checks
Cybersecurity

Metabase Zero-Day Forces Patch And Breach Checks

BleepingComputer reported active exploitation of a critical Metabase SQL injection zero-day affecting cloud and self-hosted deployments, with Framework and Tally disclosing customer data exposure.

ClickFix Attack Uses Browser Cache To Hide Malware Payload
Cybersecurity

ClickFix Attack Uses Browser Cache To Hide Malware Payload

Microsoft Threat Intelligence traced a ClickFix cache-smuggling method that preloads malware into browser caches, then uses file size checks and a pasted Run command to launch later credential-theft stages.

Keep Reading

More Stories

Latest
Singapore Online Shoppers Rank Lowest For Savvy Buying In Southeast AsiaFintech & Digital PaymentsOct 7, 2026Singapore Online Shoppers Rank Lowest For Savvy Buying In Southeast AsiaA Cube-Lazada study covered by Asian Business Review found only 9% of Singapore online shoppers qualify as savvy, with marketplace exposure and purchase protection among the main gaps.Saudi World Cup Contractor Hack Exposes 1.5 Million Files, Cyber Group SaysCybersecurityOct 7, 2026Saudi World Cup Contractor Hack Exposes 1.5 Million Files, Cyber Group SaysA cyber monitor identified a breach at a Saudi construction consortium linked to Jeddah Central Stadium, with about 17 terabytes of project and employee data reportedly stolen.Hamilton County Schools Starts K-12 Quantum Curriculum With TN QuantumWorksSportsOct 7, 2026Hamilton County Schools Starts K-12 Quantum Curriculum With TN QuantumWorksHamilton County Schools is using TN QuantumWorks curriculum from Chattanooga Quantum Collaborative and Thinking Media to introduce quantum concepts across grade levels as EPB adds a $22 million quantum computer.SUBCO Weighs Australia Cable Ship As Repair Capacity Shifts Toward 2030PoliticsOct 7, 2026SUBCO Weighs Australia Cable Ship As Repair Capacity Shifts Toward 2030SUBCO is considering an uncrewed survey vessel and a US$165 million cable-laying ship as Australia looks for more certain submarine cable survey and repair capacity beyond 2030.Nettle Raises $4.8 Million To Expand AI Insurance InspectionsReal EstateOct 7, 2026Nettle Raises $4.8 Million To Expand AI Insurance InspectionsIrish-founded Nettle raised a $4.8 million seed round led by MTech Capital to expand its AI insurance inspection platform across the US and Europe.Alliance Backs Kenya’s Cloud9 With $500,000 for Cross-Border PaymentsCapital & PolicyOct 7, 2026Alliance Backs Kenya’s Cloud9 With $500,000 for Cross-Border PaymentsAlliance invested $500,000 in Kenyan fintech Cloud9 as the company expands from digital banking into cross-border payments, stablecoin settlement and business accounts after two acquisitions.Googlebook Launch Leaves Samsung Phones Waiting For Better Together SupportDevices & Consumer TechOct 7, 2026Googlebook Launch Leaves Samsung Phones Waiting For Better Together SupportGooglebook laptops launched with Better Together phone features limited to Pixel devices, while Google says Samsung support for Android 17 phones will arrive in the coming weeks.AstaBrief Gives Asta An Open 8B Fast Mode For Scientific ReportsCapital & PolicyOct 7, 2026AstaBrief Gives Asta An Open 8B Fast Mode For Scientific ReportsAi2 released AstaBrief 8B as an open-weights report-generation model for Asta, with a one-pass pipeline that averaged 51.1 seconds per report in Fast mode.Atlassian Warns Data Centre Admins To Patch Critical File Access FlawCybersecurityOct 7, 2026Atlassian Warns Data Centre Admins To Patch Critical File Access FlawAtlassian is urging Data Centre customers to patch CVE-2026-21589, a critical flaw that can let unauthenticated attackers read specific web-root files.Finland Halts Work at Two Google Data-Centre SitesEconomyOct 7, 2026Finland Halts Work at Two Google Data-Centre SitesFinland’s environmental supervisor ordered preparatory work to stop at Google-linked data-centre sites in Muhos and Kajaani while Tuike Finland answers questions over forest clearance and environmental assessment requirements.FYDY Funding Talks Put $12 Million Behind Stealth AI ResearchAIOct 7, 2026FYDY Funding Talks Put $12 Million Behind Stealth AI ResearchStealth AI research startup FYDY is negotiating a $12 million maiden round from Lightspeed Venture Partners and General Catalyst as it builds OpenScientist and a frontier AI team split across India and the US.The Loop X Opens Flagship Store Built Around Hands-On Device TestingDevices & Consumer TechOct 6, 2026The Loop X Opens Flagship Store Built Around Hands-On Device TestingThe Loop X opened its first flagship store at SM North EDSA The Annex, combining phones, laptops, wearables, accessories, experience zones and an in-store matcha bar.