FTP Banners Abused as Dead Drop Resolvers
Score: 8/10

FTP Banners Abused as Dead Drop Resolvers

Threat actors are abusing FTP banners as Dead Drop Resolvers (DDRs) to deliver novel RATs, E4del and PINHOLE, using legitimate services like Pinterest and SurveyMonkey for configuration retrieval.

Executive Summary

The SOCRadar Threat Research Unit (STRU) has identified a novel delivery mechanism where threat actors use FTP banners to host malicious commands, effectively acting as Dead Drop Resolvers (DDRs). This activity, active since July 2026, has led to the discovery of two undocumented Remote Access Trojans (RATs): E4del, a modular Electron-based implant, and PINHOLE, a sophisticated multi-stage RAT.

E4del masquerades as a signed Discord binary and uses tiered jitter to evade network detection, while PINHOLE employs advanced evasion techniques such as Halo’s Gate, shellcode fluctuation, and Early Bird APC injection. PINHOLE further obscures its infrastructure by resolving C2 addresses through Pinterest and SurveyMonkey, and proxying traffic via Cloudflare Workers.

These campaigns demonstrate a high degree of technical proficiency in bypassing endpoint security (EDR) and network monitoring. The use of high-reputation web services as DDRs and the abuse of standard protocols like FTP for staging indicate a persistent shift toward living-off-trusted-services to maintain long-term access.

Key Details

Threat Name

PINHOLE RAT

Affects

—

Adversary

—

Malware/Tools

E4del, PINHOLE, Donut

Report Score

8out of 10
Quality Score
Good
IOC Quality9
TTP Details9
Detection Guidance6
Enterprise Relevance8
Clarity & Structure8
Technical Depth9

Sources