Threat Intelligence Attackers use FTP banners to hide new E4del and PINHOLE RATs August 21, 2026 Share By SC Staff (Adobe Stock) Threat actors are employing a novel technique of hiding commands within FTP banners to deliver two previously undocumented remote access trojans, E4del and PINHOLE, according to SOCRadar. This unusual method was first observed in July by MalwareHunterTeam and involves using shortcut files and FTP server banners as dead-drop resolvers to retrieve commands, with further coverage provided by Bleeping Computer. The attack chain begins with a ZIP archive, likely distributed via phishing, which initiates an LNK-based infection. This process leads to the deployment of the E4del and PINHOLE RATs. E4del, disguised as a Discord application, is a Node.js-based RAT capable of executing commands, capturing screenshots, and downloading further payloads. PINHOLE, a more sophisticated RAT, retrieves its command and control configuration from Pinterest pins and SurveyMonkey surveys, making it resilient to takedowns. It employs techniques like shellcode fluctuation and APC injection into legitimate processes to minimize its footprint. PINHOLE supports numerous commands, including file manipulation and credential theft. While this FTP banner technique is versatile, it is considered less stealthy than traditional web-based dead-drop resolvers due to the unusual nature of FTP connections to unknown servers. Researchers note that this method could be adapted for social engineering campaigns. Source: Bleeping Computer SC Staff Related Threat Intelligence Network of 77 Firefox extensions linked to crypto theft uncovered SC Staff August 20, 2026 Socket researchers identified 40 malicious extensions and 37 others disguised as unrelated utilities, all linked through shared code, infrastructure, and publishing artifacts. Threat Intelligence Cybercriminals invest millions in expired domains for illicit activities SC Staff August 14, 2026 These "dropcatch" domains are attractive to threat actors because they retain trust, backlinks, and web traffic from their previous legitimate use, making them appear more favorable to security systems than new registrations. Threat Intelligence Ukraine shuts down 94 fraudulent call centers in nationwide crackdown SC Staff August 14, 2026 The crackdown, which involved 411 searches, targeted call centers where operators impersonated bank officials, brokers, and law enforcement. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Account Harvesting Backdoor Deauthentication Attack Defacement Dictionary Attack Disruption Distributed Scans DumpSec Password Cracking Reconnaissance You can skip this ad in 5 seconds