Threat actors are employing a novel technique of hiding commands within FTP banners to deliver two previously undocumented remote access trojans, E4del and PINHOLE, according to SOCRadar. This unusual method was first observed in July by MalwareHunterTeam and involves using shortcut files and FTP server banners as dead-drop resolvers to retrieve commands, with further coverage provided by Bleeping Computer.The attack chain begins with a ZIP archive, likely distributed via phishing, which initiates an LNK-based infection. This process leads to the deployment of the E4del and PINHOLE RATs. E4del, disguised as a Discord application, is a Node.js-based RAT capable of executing commands, capturing screenshots, and downloading further payloads. PINHOLE, a more sophisticated RAT, retrieves its command and control configuration from Pinterest pins and SurveyMonkey surveys, making it resilient to takedowns. It employs techniques like shellcode fluctuation and APC injection into legitimate processes to minimize its footprint.PINHOLE supports numerous commands, including file manipulation and credential theft. While this FTP banner technique is versatile, it is considered less stealthy than traditional web-based dead-drop resolvers due to the unusual nature of FTP connections to unknown servers. Researchers note that this method could be adapted for social engineering campaigns.Source: Bleeping Computer
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
