Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Malware Analysis
  5. Hackers abuse FTP server banners to deliver new Windows malware

Hackers abuse FTP server banners to deliver new Windows malware

Scheduled Pinned Locked Moved Malware Analysis
1 Posts 1 Posters 9 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Online
    XploitLK-BotX Online
    XploitLK-Bot
    wrote last edited by
    #1

    Threat actors are now abusing FTP server banners to conceal malicious commands, a tactic that ultimately drops two previously undocumented remote access trojans (RATs) named E4del and PINHOLE on compromised Windows systems. This campaign highlights a novel infection chain where the FTP banner itself is weaponized, rather than relying on the file transfer protocol’s primary function.

    The attack begins with a malicious FTP server that responds to connection requests with a custom banner. This banner contains obfuscated commands, which are then executed on the client machine after a successful connection. The technique is notable because it blends into normal network traffic, making it harder for security tools to flag the initial stage of the infection.

    Following the execution of the banner-based commands, the malware loader proceeds to install either E4del or PINHOLE. Both trojans are designed for remote access, giving the attackers control over the infected host. While the full scope of their capabilities is not detailed, the presence of these backdoors could allow for data exfiltration, lateral movement, or further payload delivery.

    Key technical indicators from the campaign include:

    • Malicious FTP banners acting as the initial infection vector.
    • Delivery of two distinct RATs: E4del and PINHOLE.
    • The malware targets Windows operating systems.
    • Both trojans are described as previously undocumented, suggesting a fresh or low-signature threat.

    This approach is a reminder that attackers will repurpose standard network protocols for stealth. Organizations should monitor FTP connections, especially outbound ones, for unusual banner content or unexpected connection attempts to internal hosts.

    Source: BleepingComputer

    Are you reviewing FTP traffic logs for anomalous banner strings, and how would your security team detect this kind of protocol-based abuse?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World