logo

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

ID: 46d0cb01-19d4-55c0-a3a2-549613f07c00

STIX ID: report--46d0cb01-19d4-55c0-a3a2-549613f07c00

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers observed a novel campaign using FTP banners as dead drop resolvers to deliver two RAT families — E4del (Node.js/Electron-based, dynamic jittered beaconing) and PINHOLE (sophisticated loader using Cloudflare Workers, APC injection and multi-layer unpacking). The report includes delivery chains (LNK/WebDAV/PowerShell), detailed TTPs, RAT capabilities (remote shell, file exfiltration, screenshots, remote execution), and IoCs such as multiple FTP IPs, domains and a monitoring panel URL; the campaign appears technically advanced but still in early stages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.