Cybersecurity researchers have identified a novel malware delivery campaign using FTP banners as dead drop resolvers (DDRs) to distribute two new remote access trojans (RATs), E4del and PINHOLE. While threat actors frequently abuse legitimate services for C2 infrastructure, this marks the first recorded instance of leveraging FTP welcome messages to fetch malicious commands.
The E4del RAT is a Node.js-based payload masquerading as a Discord application, featuring a dynamic beaconing system to evade detection. Conversely, PINHOLE is a more sophisticated threat utilizing high-reputation platforms like Pinterest for DDR functionality and employing techniques such as Halo's Gate and Early Bird APC Injection to bypass security software.
Top comments (0)