Find notable cyber news and cases, enriched with sources, timelines, and signals.

E4del and PINHOLE Windows RAT activity via FTP-banner dead-drop resolvers

Malware Activity
First reported
Last updated
Happening score
H score 29
2 unique sources, 2 articles

Summary

Hide ▲

SOCRadar reported a new campaign abusing FTP banners as dead drop resolvers to deliver two previously unreported Windows RATs, E4del and PINHOLE. The activity was said to be spotted in the wild for the first time, with an infection chain that used Spanish-language voucher-claim lures, .LNK files, and FTP-to-WebDAV staging before executing payloads on Windows systems. E4del was described as a Node.js-based RAT embedded in a digitally signed Electron app masquerading as Discord, while PINHOLE used Pinterest and SurveyMonkey as DDRs and proxied communication through Cloudflare Workers. The operation also included a dedicated FTP Stats Panel, which SOCRadar said showed only 11 execution events at the time of analysis.

Related Happenings

Operation QUICSILVER Myanmar espionage campaign

Campaign
H score32 First: 24.08.2026 14:51 Last: 24.08.2026 14:51 Sources 1

About this happening: The Operation QUICSILVER espionage campaign is actively targeting Myanmar government and information technology sectors with graduation ceremony invitation lures that...

FTP-banner dead-drop resolver malware delivery campaign

Campaign
H score44 First: 21.08.2026 14:00 Last: 21.08.2026 14:00 Sources 1

How related: Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE.

About this happening: A campaign is using FTP banners as dead-drop resolvers to deliver the E4del and PINHOLE Windows RATs, creating a command-delivery path that hides instructions...

Fake Xeno Executor Java RAT and infostealer malware

Malware Activity
H score30 First: 03.08.2026 22:25 Last: 03.08.2026 22:25 Sources 1

About this happening: Fake Xeno Executor installers are infecting Roblox players through gaming forums, Discord communities, and compromised or impersonated accounts, with victims runni...

NightLedger, BridgeHead, and ArcBridge covert-access deployment

Malware Activity
H score23 First: 28.07.2026 14:55 Last: 28.07.2026 14:55 Sources 1

About this happening: Nimbus Manticore has expanded its covert-access malware set with NightLedger, BridgeHead, and ArcBridge in intrusions across the Middle East, Africa, and Sou...

Latest development: 26.08.2026 18:35

Group-IB found additional Tortoiseshell infrastructure spanning Europe and the Middle East, including a reverse SSH tunneling tool that masquerades as the Windows Terminal Server SDK API and connects to 172.86.98[.]113 on port 443, plus a C++ backdoor that mimics wtsapi32.dll and uses hard-coded C2 servers to download and upload files, execute binaries or DLLs, gather host information, list directories, and delete files.

ACR Stealer enterprise infostealer surge

Malware Activity
H score29 First: 18.07.2026 17:17 Last: 18.07.2026 17:17 Sources 1

About this happening: ACR Stealer attacks surged against enterprise customers, putting browser-stored passwords, authentication tokens, cookies, and sensitive documents at risk....

Timeline

  1. 21.08.2026 14:00 3 articles · 13d ago

    FTP banners deliver E4del and PINHOLE in a Windows malware campaign

    Initial Disclosure

    Threat actors abuse FTP server banners as dead-drop resolvers to deliver two previously undocumented Windows RATs, E4del and PINHOLE, against affected Windows systems. The infection chain starts with a ZIP archive that triggers LNK-based execution, likely through phishing, and both routes retrieve a PowerShell script from FTP banners. E4del is a Node.js-based RAT packaged inside a digitally signed Electron application masquerading as Discord, while PINHOLE pulls C2 configuration from Pinterest pins and SurveyMonkey survey questions.

    Show sources