E4del and PINHOLE Windows RAT activity via FTP-banner dead-drop resolvers
Malware Activity
Summary
Hide ▲
Show ▼
SOCRadar reported a new campaign abusing FTP banners as dead drop resolvers to deliver two previously unreported Windows RATs, E4del and PINHOLE. The activity was said to be spotted in the wild for the first time, with an infection chain that used Spanish-language voucher-claim lures, .LNK files, and FTP-to-WebDAV staging before executing payloads on Windows systems. E4del was described as a Node.js-based RAT embedded in a digitally signed Electron app masquerading as Discord, while PINHOLE used Pinterest and SurveyMonkey as DDRs and proxied communication through Cloudflare Workers. The operation also included a dedicated FTP Stats Panel, which SOCRadar said showed only 11 execution events at the time of analysis.
Related Happenings
Operation QUICSILVER Myanmar espionage campaign
Campaign
H score32
First: 24.08.2026 14:51
Last: 24.08.2026 14:51
Sources 1
About this happening:
The Operation QUICSILVER espionage campaign is actively targeting Myanmar government and information technology sectors with graduation ceremony invitation lures that...
Operation QUICSILVER Myanmar espionage campaign
CampaignAbout this happening: The Operation QUICSILVER espionage campaign is actively targeting Myanmar government and information technology sectors with graduation ceremony invitation lures that...
FTP-banner dead-drop resolver malware delivery campaign
Campaign
H score44
First: 21.08.2026 14:00
Last: 21.08.2026 14:00
Sources 1
How related:
Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE.
About this happening:
A campaign is using FTP banners as dead-drop resolvers to deliver the E4del and PINHOLE Windows RATs, creating a command-delivery path that hides instructions...
FTP-banner dead-drop resolver malware delivery campaign
CampaignHow related: Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE.
About this happening: A campaign is using FTP banners as dead-drop resolvers to deliver the E4del and PINHOLE Windows RATs, creating a command-delivery path that hides instructions...
Fake Xeno Executor Java RAT and infostealer malware
Malware Activity
H score30
First: 03.08.2026 22:25
Last: 03.08.2026 22:25
Sources 1
About this happening:
Fake Xeno Executor installers are infecting Roblox players through gaming forums, Discord communities, and compromised or impersonated accounts, with victims runni...
Fake Xeno Executor Java RAT and infostealer malware
Malware ActivityAbout this happening: Fake Xeno Executor installers are infecting Roblox players through gaming forums, Discord communities, and compromised or impersonated accounts, with victims runni...
NightLedger, BridgeHead, and ArcBridge covert-access deployment
Malware Activity
H score23
First: 28.07.2026 14:55
Last: 28.07.2026 14:55
Sources 1
About this happening:
Nimbus Manticore has expanded its covert-access malware set with NightLedger, BridgeHead, and ArcBridge in intrusions across the Middle East, Africa, and Sou...
NightLedger, BridgeHead, and ArcBridge covert-access deployment
Malware ActivityAbout this happening: Nimbus Manticore has expanded its covert-access malware set with NightLedger, BridgeHead, and ArcBridge in intrusions across the Middle East, Africa, and Sou...
Latest development: 26.08.2026 18:35
Group-IB found additional Tortoiseshell infrastructure spanning Europe and the Middle East, including a reverse SSH tunneling tool that masquerades as the Windows Terminal Server SDK API and connects to 172.86.98[.]113 on port 443, plus a C++ backdoor that mimics wtsapi32.dll and uses hard-coded C2 servers to download and upload files, execute binaries or DLLs, gather host information, list directories, and delete files.
ACR Stealer enterprise infostealer surge
Malware Activity
H score29
First: 18.07.2026 17:17
Last: 18.07.2026 17:17
Sources 1
About this happening:
ACR Stealer attacks surged against enterprise customers, putting browser-stored passwords, authentication tokens, cookies, and sensitive documents at risk....
ACR Stealer enterprise infostealer surge
Malware ActivityAbout this happening: ACR Stealer attacks surged against enterprise customers, putting browser-stored passwords, authentication tokens, cookies, and sensitive documents at risk....
Timeline
-
21.08.2026 14:00 3 articles · 13d ago
FTP banners deliver E4del and PINHOLE in a Windows malware campaign
Initial DisclosureThreat actors abuse FTP server banners as dead-drop resolvers to deliver two previously undocumented Windows RATs, E4del and PINHOLE, against affected Windows systems. The infection chain starts with a ZIP archive that triggers LNK-based execution, likely through phishing, and both routes retrieve a PowerShell script from FTP banners. E4del is a Node.js-based RAT packaged inside a digitally signed Electron application masquerading as Discord, while PINHOLE pulls C2 configuration from Pinterest pins and SurveyMonkey survey questions.
Show sources
- Hackers abuse FTP server banners to deliver new Windows malware — www.bleepingcomputer.com — 21.08.2026 14:00
- Hackers abuse FTP server banners to deliver new Windows malware — www.bleepingcomputer.com — 21.08.2026 14:00
- E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands — thehackernews.com — 25.08.2026 14:33