FTP welcome messages now smuggle commands to new Windows RATs

Two new Windows trojans pull their next commands straight from FTP server banners in a first-seen delivery trick.

CSBadmin
2 Min Read

Security researchers have spotted attackers using FTP server banners, the welcome text a server sends on connection, as dead drop resolvers to feed commands to two previously unreported Windows remote access trojans.

SOCRadar, which documented the campaigns, says it is the first time the technique has been observed in the wild, though MalwareHunterTeam highlighted the method last month. Malware stagers fetch commands directly from the protocol’s initial response instead of a web page, though the approach is less stealthy than traditional web-based dead drops since FTP connections to unknown servers stand out.

One chain starts with Spanish-language voucher lures and a Windows Shortcut file. The shortcut pulls its next command straight from an FTP banner, then reaches a WebDAV server to run a DLL export through rundll32. ClearFake campaigns use the same WebDAV trick, with ClickFix decoys delivering WordlistLoader and Amatera Stealer.

The chain ultimately delivers E4del, a Node.js RAT packed inside a signed Electron application masquerading as Discord. It offers a reverse shell, screenshots, live desktop streaming, and file theft, with a tiered jitter system that stretches beacon intervals from milliseconds to seconds to blend into network traffic.

The second trojan, PINHOLE, is more advanced. It uses high-reputation platforms like Pinterest and SurveyMonkey as dead drops and proxies command traffic through Cloudflare Workers, unpacks through six layers, and injects into a suspended process using the Halo’s Gate evasion technique. Operators track campaign stats from a dedicated FTP panel that showed only 11 execution events, suggesting the effort is young.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.