<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Hackers abuse FTP server banners to deliver new Windows malware]]></title><description><![CDATA[<p dir="auto">Threat actors are now abusing FTP server banners to conceal malicious commands, a tactic that ultimately drops two previously undocumented remote access trojans (RATs) named <strong>E4del</strong> and <strong>PINHOLE</strong> on compromised Windows systems. This campaign highlights a novel infection chain where the FTP banner itself is weaponized, rather than relying on the file transfer protocol’s primary function.</p>
<p dir="auto">The attack begins with a malicious FTP server that responds to connection requests with a custom banner. This banner contains obfuscated commands, which are then executed on the client machine after a successful connection. The technique is notable because it blends into normal network traffic, making it harder for security tools to flag the initial stage of the infection.</p>
<p dir="auto">Following the execution of the banner-based commands, the malware loader proceeds to install either <strong>E4del</strong> or <strong>PINHOLE</strong>. Both trojans are designed for remote access, giving the attackers control over the infected host. While the full scope of their capabilities is not detailed, the presence of these backdoors could allow for data exfiltration, lateral movement, or further payload delivery.</p>
<p dir="auto">Key technical indicators from the campaign include:</p>
<ul>
<li>Malicious FTP banners acting as the initial infection vector.</li>
<li>Delivery of two distinct RATs: <strong>E4del</strong> and <strong>PINHOLE</strong>.</li>
<li>The malware targets <strong>Windows</strong> operating systems.</li>
<li>Both trojans are described as previously undocumented, suggesting a fresh or low-signature threat.</li>
</ul>
<p dir="auto">This approach is a reminder that attackers will repurpose standard network protocols for stealth. Organizations should monitor FTP connections, especially outbound ones, for unusual banner content or unexpected connection attempts to internal hosts.</p>
<p dir="auto">Source: <a href="https://www.bleepingcomputer.com/news/security/hackers-abuse-ftp-server-banners-to-deliver-new-windows-malware" target="_blank" rel="noopener noreferrer nofollow ugc">BleepingComputer</a></p>
<p dir="auto">Are you reviewing FTP traffic logs for anomalous banner strings, and how would your security team detect this kind of protocol-based abuse?</p>
]]></description><link>https://xploitlk.com/topic/57/hackers-abuse-ftp-server-banners-to-deliver-new-windows-malware</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 12:35:50 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/57.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 23 Aug 2026 05:39:41 GMT</pubDate><ttl>60</ttl></channel></rss>