Find notable cyber news and cases, enriched with sources, timelines, and signals.

FTP-banner dead-drop resolver malware delivery campaign

Campaign
First reported
Last updated
Happening score
H score 44
2 unique sources, 2 articles

Summary

Hide ▲

A campaign is using FTP banners as dead-drop resolvers to deliver the E4del and PINHOLE Windows RATs, creating a command-delivery path that hides instructions inside normal FTP greetings. SOCRadar said the operation was weaponized since early July 2026 and remained active in August 2026, with ZIP archives and .LNK execution likely tied to phishing. E4del is embedded in a digitally signed Electron app masquerading as Discord, while PINHOLE pulls C2 details from Pinterest and SurveyMonkey and can proxy traffic through Cloudflare Workers. The campaign also uses staged infrastructure, including 157.254.194[.]31:21, 167.148.41[.]164:21, 209.99.185[.]38:21, and a FTP Stats Panel at 69.48.228[.]126:5000 that showed 11 execution events at the time of analysis.

Related Happenings

Operation QUICSILVER Myanmar espionage campaign

Campaign
H score32 First: 24.08.2026 14:51 Last: 24.08.2026 14:51 Sources 1

About this happening: The Operation QUICSILVER espionage campaign is actively targeting Myanmar government and information technology sectors with graduation ceremony invitation lures that...

E4del and PINHOLE Windows RAT activity via FTP-banner dead-drop resolvers

Malware Activity
H score29 First: 21.08.2026 14:00 Last: 21.08.2026 14:00 Sources 1

How related: Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE.

About this happening: SOCRadar reported a new campaign abusing FTP banners as dead drop resolvers to deliver two previously unreported Windows RATs, E4del and PINHOLE. The activ...

Silver Fox MODBEACON Rust RAT activity

Malware Activity
H score23 First: 10.07.2026 16:15 Last: 10.07.2026 16:15 Sources 1

About this happening: The Silver Fox ecosystem has been tied to MODBEACON, a Rust-based remote access trojan that gives operators encrypted C2 and modular control over infected hosts. T...

Gremlin stealer modular toolkit evolution

Malware Activity
H score21 First: 15.05.2026 17:19 Last: 15.05.2026 17:19 Sources 1

About this happening: The Gremlin stealer malware has expanded into a modular toolkit with session-hijacking and crypto clipping capabilities, raising the risk of credential theft and a...

Vidar infostealer market rise and distribution expansion

Malware Activity
H score30 First: 28.04.2026 22:07 Last: 28.04.2026 22:07 Sources 1

About this happening: Vidar remains a long-running infostealer threat, with Aryaka reporting a fresh Windows campaign in recent weeks that used a PowerShell infection chain, the...

Timeline

  1. 21.08.2026 14:00 3 articles · 13d ago

    Threat actors use FTP banners to deliver E4del and PINHOLE

    Initial Disclosure

    Threat actors are abusing FTP server banners as dead-drop resolvers to hide commands that deliver two previously undocumented Windows RATs, E4del and PINHOLE. SOCRadar says the campaign was weaponized since early July 2026, remained operational in August 2026, and used a ZIP archive that triggers an LNK-based infection chain, likely through phishing, with both infection routes retrieving a PowerShell script from FTP banners. E4del is packaged in a digitally signed Electron application that masquerades as Discord, while PINHOLE pulls C2 configuration from Pinterest pins and SurveyMonkey survey questions.

    Show sources