Hackers use FTP server banners to deliver two new Windows remote access trojans

Threat actors are embedding malicious commands in FTP server greeting messages to deliver two previously undocumented remote access trojans named E4del and PINHOLE, security researchers at SOCRadar report. The technique, first observed in July, uses shortcut files (.LNK) to retrieve PowerShell scripts hidden in FTP banners, likely deployed through phishing attacks.
E4del is a Node.js-based RAT packaged as a fake Discord application that can run commands, capture screenshots and stream desktops. PINHOLE uses a smaller footprint and retrieves its configuration from Pinterest pins and SurveyMonkey questions, supporting 14 commands including file theft and credential stealing. SOCRadar says the technique remains in use as of August, though FTP connections to unknown servers are more easily detected than traditional web-based dead-drop resolvers like X or GitHub, Bill Toulas reports for BleepingComputer.