Threat actors are exploiting FTP server banners as a covert channel to hide and deliver malicious commands. The campaign introduces two previously undocumented remote access trojans named E4del and PINHOLE. By abusing FTP banners, attackers can blend malicious activity within legitimate network traffic, making detection more difficult. This technique represents a novel delivery mechanism for malware distribution targeting Windows systems. The use of two distinct RATs suggests a sophisticated, multi-stage operation. The discovery highlights an emerging trend of abusing legitimate protocol features for command delivery.
E4del, PINHOLE