Hackers abuse FTP server banners to deliver new Windows malware
Summary
Threat actors are exploiting FTP server banners to embed hidden commands that distribute two new, previously undocumented Windows remote access trojans (RATs) called E4del and PINHOLE. These RATs allow attackers to gain unauthorized access and control over compromised systems.
IFF Assessment
FOE
This article details a new technique used by threat actors to deliver malware, which poses a direct threat to defenders.
Defender Context
Defenders should be aware of this novel attack vector where seemingly innocuous FTP banner text could contain malicious commands. Implementing stricter content filtering on FTP banners and enhancing endpoint detection to identify the newly identified E4del and PINHOLE RATs are crucial steps.