Malware

Windows Malware Delivered via FTP Server Banners

August 23, 2026 20:16 · 12 min read
Windows Malware Delivered via FTP Server Banners

Abuse of FTP Server Banners for Malware Delivery

Threat actors have been observed abusing FTP server banners to hide commands that deliver two previously undocumented remote access trojans, E4del and PINHOLE. According to MalwareHunterTeam, this unusual technique was first observed in July 2026, in an attack that used shortcut files (.LNK) and FTP server banners as dead-drop resolvers (DDR) to retrieve commands.

FTP banners are text strings used by servers as a greeting message for connecting hosts before they log in. By embedding commands in the initial response sent when a compromised system connects to an FTP server, a malware stager can receive instructions from a remote server. Researchers at SOCRadar expanded their investigation and found that this technique remains in use, with new infrastructure observed as recently as August 2026.

Infection Chain and Malware Delivery

The observed attacks start with a ZIP archive that triggers an LNK-based infection chain. The researchers note that the initial compromise likely occurs through phishing. The infection chain delivers two remote access trojans (RATs) via two distinct infection routes, both retrieving a PowerShell script from FTP banners.

E4del is a Node.js-based RAT packaged inside a digitally signed Electron application that masquerades as Discord. The RAT supports running commands through persistent or temporary shells, capturing screenshots, streaming the desktop over WebSockets, and downloading and executing additional payloads.

PINHOLE retrieves its C2 configuration from Pinterest pins and SurveyMonkey survey questions, a tactic that offers versatility and resilience to take-downs. The malware leaves a minimal footprint on the host, using shellcode fluctuation to keep only one 4KB section of the payload in memory at a time, and injecting the final assembly into a suspended ApplicationFrameHost.exe process via Early Bird APC injection.

Supported Commands and Campaign Analysis

PINHOLE supports 14 commands, including file enumeration, uploading and downloading files, command execution, process management, capturing screenshots, and deploying a module for stealing credentials stored in browsers. At the time of analysis, the PINHOLE script counted only 11 execution events, suggesting that the campaign was in an early stage.

While abusing FTP banners to deliver commands is a novel alternative, SOCRadar notes that the approach is less stealthy than traditional web-based DDRs (e.g., X, GitHub, YouTube) because FTP connections to unknown servers are more likely to stand out. The technique is very versatile and could "easily" be adapted for ClickFix social engineering campaigns.

Defender Guidance and Prevention

SOCRadar's report provides indicators of compromise that could help defenders identify the malicious infrastructure as well as infected machines on the network. Once attackers have valid credentials, only 37% of their actions are blocked, highlighting the importance of robust defense strategies.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments, offering valuable insights for defenders. By understanding the tactics, techniques, and procedures (TTPs) used by threat actors, defenders can improve their prevention and detection capabilities.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free