Hackers abuse FTP server banners to deliver new Windows malware

Summary

Threat actors are exploiting FTP server banners to embed hidden commands that distribute two new, previously undocumented Windows remote access trojans (RATs) called E4del and PINHOLE. These RATs allow attackers to gain unauthorized access and control over compromised systems.

IFF Assessment

FOE

This article details a new technique used by threat actors to deliver malware, which poses a direct threat to defenders.

Defender Context

Defenders should be aware of this novel attack vector where seemingly innocuous FTP banner text could contain malicious commands. Implementing stricter content filtering on FTP banners and enhancing endpoint detection to identify the newly identified E4del and PINHOLE RATs are crucial steps.

Read Full Story →