threat-intel
E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
High
Summary
Threat actors are utilizing FTP banner responses as dead drop resolvers to deliver two new remote access trojans, E4del and PINHOLE RAT. E4del, a Node.js-based RAT, employs a dynamic beaconing system to blend in with network traffic and evade detection. PINHOLE RAT leverages high-reputation platforms like Pinterest and SurveyMonkey to establish C2 communication, utilizing sophisticated techniques like APC Injection to bypass security software and evade traditional antivirus systems. The campaign is currently in its early stages, with limited execution events observed.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
