E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

Summary

Cybersecurity researchers have identified a new campaign utilizing FTP banners as dead drop resolvers (DDRs) to distribute two new remote access trojans (RATs) named E4del and PINHOLE. This tactic allows threat actors to conceal their command-and-control (C2) infrastructure by embedding malicious instructions within seemingly innocuous FTP banner messages.

IFF Assessment

FOE

This campaign's use of FTP banners as dead drops to deliver RATs represents a new evasion technique that makes it harder for defenders to detect and block malware command-and-control traffic.

Defender Context

Defenders should be aware of this novel technique where FTP banners are being weaponized to hide C2 communications and deliver malware. Monitoring unusual FTP banner content and unusual outbound connections originating from FTP servers could help identify such campaigns. This highlights the need for layered security approaches that inspect various protocols for malicious activity.

Read Full Story →