Interestana
Home/News/Hackers Abuse FTP Banners for New Windows Malware Delivery
BleepingComputer3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Hackers Abuse FTP Banners for New Windows Malware Delivery

Threat actors are actively exploiting the banners of File Transfer Protocol (FTP) servers to conceal malicious commands, enabling the delivery of two previously undocumented remote access trojans (RATs) to Windows systems. These newly identified RATs, named E4del and PINHOLE, represent a novel approach to malware distribution by embedding executable code within the informational text displayed by FTP servers upon connection. This technique allows attackers to bypass traditional security measures that might scrutinize file transfers or network traffic for malicious payloads, as the commands are hidden in plain sight within server banner messages.

Researchers at Palo Alto Networks' Unit 42 detailed this discovery, noting that the attackers leverage these FTP banners to host staging servers. When a targeted Windows machine connects to a compromised FTP server, the banner text is retrieved. This text contains encoded commands that instruct the victim machine to download and execute the E4del or PINHOLE malware. The use of FTP banners as a covert channel for command and control (C2) infrastructure is a significant development in the evolving tactics of cybercriminals. This method allows for a degree of obfuscation, as the banner text itself is not typically scanned for malicious content by many security solutions.

E4del, one of the identified RATs, is designed to provide attackers with extensive control over compromised systems. Its capabilities include executing arbitrary commands, uploading and downloading files, and capturing screenshots, all of which are standard functionalities for remote access trojans aimed at espionage or further system compromise. The other RAT, PINHOLE, exhibits similar functionalities, suggesting a coordinated effort by the threat actors to deploy a suite of tools for persistent access and data exfiltration. The specific details regarding the initial infection vector that leads a Windows machine to connect to these compromised FTP servers remain under investigation, but it is likely to involve social engineering tactics or exploitation of other vulnerabilities.

The discovery of E4del and PINHOLE highlights the persistent innovation within the cyber threat landscape. Attackers are continuously seeking new and unconventional methods to deliver malware and maintain command and control over infected networks. The abuse of FTP banners represents a sophisticated evasion technique that security vendors and defenders must now account for. Organizations are advised to review their network security configurations, monitor FTP server logs for unusual banner content, and ensure that endpoint security solutions are updated to detect and block these new RATs. The ongoing analysis by Unit 42 aims to provide further insights into the full scope of this campaign, including the attribution of the threat actors and the broader impact on targeted entities.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next