← Blog · · df00tech

FTP Banner Steganography: New E4del and PINHOLE RATs Reported

security-news technique

BleepingComputer reports that threat actors are abusing FTP server banners — the plaintext welcome message an FTP server sends on connection — to hide commands used to deliver two previously undocumented remote access trojans, named E4del and PINHOLE, targeting Windows systems.

What Was Reported

According to the report, attackers are embedding hidden instructions within FTP banner text as a delivery or command mechanism for the new malware families. Technical specifics on the initial access vector, the exact banner-abuse technique, and full capabilities of E4del and PINHOLE were not detailed beyond this summary; readers should consult the original reporting for further depth as it becomes available.

Why It Matters

FTP remains present in many legacy and industrial environments, and banner text is rarely inspected or logged closely by defenders — most security tooling treats it as benign metadata rather than an active content channel. If confirmed as described, this technique offers attackers a low-visibility way to stage or trigger malware delivery on Windows hosts that interact with malicious or compromised FTP servers, whether as clients or through automated scripts/tooling that parse banners.

What Defenders Should Watch For

  • Inventory and monitor any systems, scripts, or automation that connect to external FTP servers and parse or log banner responses.
  • Review network logs for outbound FTP connections (port 21 and passive-mode data ports) to unexpected or newly observed external hosts.
  • Watch for anomalous process creation or network activity on Windows endpoints shortly after FTP client sessions, which could indicate banner-triggered payload execution.
  • Flag unusually long, obfuscated, or non-standard banner strings captured in FTP session logs or proxy/IDS inspection where available.
  • Since E4del and PINHOLE are newly named and not yet well characterized publicly, prioritize behavioral and network-based detection over static signatures until more indicators emerge.

Developing Story

This is net-new intelligence with limited technical detail currently available; attribution, full technical mechanics, and indicators of compromise for E4del and PINHOLE have not yet been independently corroborated here. We will revisit this item as more information surfaces. Read the original report at BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.