E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
ID: 46d0cb01-19d4-55c0-a3a2-549613f07c00
STIX ID: report--46d0cb01-19d4-55c0-a3a2-549613f07c00
Feed Name: The Hacker News
Cybersecurity researchers observed a novel campaign using FTP banners as dead drop resolvers to deliver two RAT families — E4del (Node.js/Electron-based, dynamic jittered beaconing) and PINHOLE (sophisticated loader using Cloudflare Workers, APC injection and multi-layer unpacking). The report includes delivery chains (LNK/WebDAV/PowerShell), detailed TTPs, RAT capabilities (remote shell, file exfiltration, screenshots, remote execution), and IoCs such as multiple FTP IPs, domains and a monitoring panel URL; the campaign appears technically advanced but still in early stages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
