By Interestana AI Editorial — AI-drafted, human-overseen. How we report
FTP Banners Used as Malware Command Dead Drops

Cybersecurity researchers have identified a novel campaign that leverages File Transfer Protocol (FTP) banners to act as dead drop resolvers (DDRs), facilitating the delivery of two previously undocumented remote access trojans (RATs) named E4del and PINHOLE. This technique allows threat actors to conceal their command-and-control (C2) infrastructure by embedding malicious instructions within the seemingly innocuous text displayed when a user connects to an FTP server. Threat actors have historically abused legitimate services to mask their C2 servers and evade detection by blending in with normal network traffic, but this particular method of utilizing FTP banners represents a new evolution in their tactics. The researchers detailed their findings in a report published on March 15, 2024, highlighting the sophisticated nature of this attack vector. The E4del RAT, for instance, is designed to exfiltrate sensitive data from compromised systems, while the PINHOLE RAT is capable of establishing persistent access and executing arbitrary commands. Both RATs are equipped with functionalities that enable them to maintain communication with their operators, even when direct C2 channels are blocked or unavailable. The use of FTP banners as DDRs means that when a victim's machine attempts to connect to a compromised FTP server, the banner text is parsed for specific commands or indicators that point to the actual C2 server. This indirect method of communication adds a layer of obfuscation, making it more challenging for security tools to identify and block the malicious infrastructure. The researchers emphasized that this technique is particularly effective because FTP is a widely used protocol, and its banners are often overlooked by security monitoring systems. The campaign's discovery underscores the persistent innovation of cybercriminals in finding new ways to compromise systems and maintain control. Organizations are advised to enhance their network monitoring capabilities to detect unusual FTP banner content and to ensure that their FTP servers are secured against unauthorized access and modification. Furthermore, implementing robust endpoint detection and response (EDR) solutions can help identify the presence of E4del and PINHOLE RATs on infected systems, even if their C2 communication is masked. The ongoing evolution of these tactics necessitates a proactive and adaptive approach to cybersecurity defense, with a focus on understanding and mitigating emerging threats. The researchers did not disclose the specific threat actor group behind this campaign, but the sophistication suggests a well-resourced and organized entity. The implications of this discovery extend to various industries that rely on FTP for data transfer, making them potential targets for this new attack method. The ability to turn a standard protocol feature into a weaponized tool highlights the need for continuous vigilance and adaptation in the cybersecurity landscape.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.