Hackers Abuse FTP Server Banners to Deliver New Windows Malware
Undocumented RATs E4del and PINHOLE deployed via manipulated FTP service responses

Key Takeaways
- Threat actors are abusing FTP server banners to deliver previously undocumented Windows RATs.
- Two new malware families, E4del and PINHOLE, are being deployed in active campaigns.
- The exploitation leverages manipulated FTP service responses to hide malicious commands.
- No patch is currently available; securing FTP configurations and monitoring activity are recommended.
Quick answers
- What happened?
- Threat actors are exploiting FTP server banner configurations to conceal and execute commands that deliver two previously undocumented remote access trojans, E4del and PINHOLE, targeting Windows systems. The abuse of FTP banners allows attackers to hide malicious instructions within legitimate server responses, facilitating initial access and remote control.
- What should defenders do?
- Secure FTP server configurations by restricting banner content. Monitor for anomalous FTP activity. Apply defense-in-depth measures to prevent unauthorized command execution from FTP services.
According to a report published by BleepingComputer on August 21, 2026, threat actors are abusing FTP server banners to deliver new Windows malware. The campaign involves the deployment of two previously undocumented remote access trojans named E4del and PINHOLE. The attackers manipulate FTP server banner responses to hide commands that, when processed by FTP clients or associated automation, result in the execution of malicious payloads. The exact mechanism of how banner abuse leads to command execution remains under analysis, but the abuse allows malicious instructions to be concealed within standard FTP service responses. The report indicates that the campaign is active and ongoing. The malware, E4del and PINHOLE, provide full remote access capability to compromised Windows systems. The scale of compromise and the specific initial access vector beyond the FTP banner manipulation are not specified in the available summary. As of the report date, no patch or fix is available from vendors; mitigation is focused on securing FTP server configurations, restricting banner content, and monitoring for anomalous FTP activity. The report was sourced from BleepingComputer, and details regarding exact exploitation techniques and victim counts are pending further analysis.
Security Details
Threat actors are manipulating FTP server banner configurations to conceal and execute commands that deliver the remote access trojans E4del and PINHOLE to Windows systems. The abuse of banners allows malicious instructions to be hidden within legitimate server responses.
Mitigation
Secure FTP server configurations by restricting banner content. Monitor for anomalous FTP activity. Apply defense-in-depth measures to prevent unauthorized command execution from FTP services.
Sources
BleepingComputer
Hackers abuse FTP server banners to deliver new Windows malware
Aug 21, 2026 · 11:00
Original link
Related Security News

Star Blizzard Campaign Targets 100+ Organizations with Fake Event Invitations
Microsoft reports that the Russian state-sponsored threat actor Star Blizzard has been conducting a sustained campaign since January 2026, using fake event invitations to trick targets into installing a backdoor on Windows computers. The operation has affected more than 100 organizations, primarily in the U.S. and U.K., with victims tied to Ukraine. At least one infection has been confirmed, though the full extent of breaches and data exfiltration remains unverified.




