Hackers abuse FTP server banners to deliver new Windows malware
ID: fade4b92-b519-5479-8eab-ac1f7aa46c83
STIX ID: report--fade4b92-b519-5479-8eab-ac1f7aa46c83
Feed Name: Bleeping Computer
Researchers observed threat actors weaponizing FTP server banners as dead-drop resolvers to deliver PowerShell stagers that retrieve two previously undocumented remote access trojans: E4del (a Node.js/Electron RAT masquerading as Discord) and PINHOLE (a stealthy loader using Pinterest/SurveyMonkey for C2 and early-bird APC injection). The reported campaign starts from ZIP/LNK phishing lures, includes capabilities like remote shells, file exfiltration, credential theft modules, and provides IOCs; activity was observed from July through August 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
