logo

Hackers abuse FTP server banners to deliver new Windows malware

ID: fade4b92-b519-5479-8eab-ac1f7aa46c83

STIX ID: report--fade4b92-b519-5479-8eab-ac1f7aa46c83

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2026-08-21

Date Updated: 2026-08-21

Author: Bill Toulas

...
...

Researchers observed threat actors weaponizing FTP server banners as dead-drop resolvers to deliver PowerShell stagers that retrieve two previously undocumented remote access trojans: E4del (a Node.js/Electron RAT masquerading as Discord) and PINHOLE (a stealthy loader using Pinterest/SurveyMonkey for C2 and early-bird APC injection). The reported campaign starts from ZIP/LNK phishing lures, includes capabilities like remote shells, file exfiltration, credential theft modules, and provides IOCs; activity was observed from July through August 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.