E4del and PINHOLE RATs Exploit FTP Banners as Dead Drop Resolvers
Researchers identify campaign using legitimate FTP services to host hidden command-and-control infrastructure within banner text

Key Takeaways
- FTP banners are being used as dead drop resolvers to deliver previously unreported RATs named E4del and PINHOLE.
- Threat actors abuse legitimate FTP services to embed C2 commands within standard banner text.
- The technique helps malware blend with normal network traffic, evading detection.
Related Security News

Star Blizzard Campaign Targets 100+ Organizations with Fake Event Invitations
Microsoft reports that the Russian state-sponsored threat actor Star Blizzard has been conducting a sustained campaign since January 2026, using fake event invitations to trick targets into installing a backdoor on Windows computers. The operation has affected more than 100 organizations, primarily in the U.S. and U.K., with victims tied to Ukraine. At least one infection has been confirmed, though the full extent of breaches and data exfiltration remains unverified.




