FTP Banner Malware Campaign Uses E4del And PINHOLE RATs For Remote Access Attacks

Published:

Cybersecurity researchers have uncovered a new malware campaign that uses FTP banners as dead drop resolvers to distribute two previously undocumented remote access trojans named E4del and PINHOLE. According to SOCRadar, the campaign represents the first known instance of threat actors using FTP server welcome banners to deliver commands for malware deployment. While attackers have long relied on legitimate online services to hide command and control infrastructure within normal internet traffic, this newly observed approach introduces a different method of delivering instructions directly through the initial response sent by an FTP server. Security researchers note that although the technique is creative, it is less stealthy than traditional web based dead drop resolvers because connections to unknown FTP servers are more likely to attract attention from enterprise security tools.

One of the observed attack chains begins with Spanish language phishing lures promising voucher claims. Victims are persuaded to execute a malicious Windows shortcut file that retrieves commands from an FTP banner before connecting to a WebDAV server. The malware then downloads and launches a DLL through rundll32.exe using conhost. Researchers noted that WebDAV has recently been used in other campaigns, including ClickFix operations distributing WordlistLoader and Amatera Stealer, where compromised websites display fake CAPTCHA prompts that convince users to execute harmful commands. In the E4del campaign, the first FTP banner directs the malware to another FTP server that delivers PowerShell instructions to download a ZIP archive, extract its contents, and execute the final payload. The malware eventually installs E4del, a Node.js based remote access trojan embedded inside a digitally signed Electron application disguised as Discord. Once active, the malware can evade security tools, establish persistence, gather system information, communicate with its command server through encrypted channels, execute reverse shell commands, capture screenshots, stream the desktop, download files, and deploy additional payloads. Researchers also highlighted E4del dynamic beaconing mechanism, which changes its communication intervals depending on activity levels to better blend with normal network traffic.

The second malware family identified in the campaign is PINHOLE, which researchers believe is more sophisticated. Instead of relying solely on FTP banners, it combines the technique with trusted online platforms such as Pinterest and SurveyMonkey to retrieve command and control server information while routing communications through Cloudflare Workers. In the observed attacks, the FTP banner delivers PowerShell commands that retrieve another script from a remote server, save it temporarily, execute it, and immediately remove it to reduce forensic evidence. The script then unpacks the primary payload, which masquerades as an update utility from a fictitious company called Weston Computing Systems Ltd. Researchers found that the malware employs the Halo’s Gate technique to bypass security software before resolving additional payloads from its command infrastructure. The malware further conceals its activity by passing the payload through six unpacking layers before injecting it into a suspended legitimate process using the Early Bird APC Injection technique. This approach is designed to reduce the likelihood of detection by antivirus and endpoint security solutions while allowing the malware to execute inside a trusted Windows process.

Once fully deployed, PINHOLE provides attackers with extensive remote access capabilities through HTTP based communication with its command server. Researchers found that it supports fourteen different commands, including file and directory enumeration, file uploads and downloads, payload execution, recursive file searches, process management, screenshot capture, PowerShell execution, and interactive PowerShell sessions using anonymous pipes. SOCRadar also discovered that the operators maintain a dedicated FTP Stats Panel that tracks campaign performance by monitoring script executions, connection attempts, and unique active or blocked IP addresses interacting with the FTP infrastructure. At the time of analysis, the panel recorded only eleven execution events, suggesting that the operation remains in its early stages. Researchers warned that although the current campaign primarily relies on shortcut file phishing, the same FTP banner technique could easily be adapted for other social engineering campaigns, including ClickFix style attacks, making it a method security teams should continue to monitor.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Related articles

spot_img