Executive Summary
The SOCRadar Threat Research Unit (STRU) has identified a novel delivery mechanism where threat actors use FTP banners to host malicious commands, effectively acting as Dead Drop Resolvers (DDRs). This activity, active since July 2026, has led to the discovery of two undocumented Remote Access Trojans (RATs): E4del, a modular Electron-based implant, and PINHOLE, a sophisticated multi-stage RAT.
E4del masquerades as a signed Discord binary and uses tiered jitter to evade network detection, while PINHOLE employs advanced evasion techniques such as Halo’s Gate, shellcode fluctuation, and Early Bird APC injection. PINHOLE further obscures its infrastructure by resolving C2 addresses through Pinterest and SurveyMonkey, and proxying traffic via Cloudflare Workers.
These campaigns demonstrate a high degree of technical proficiency in bypassing endpoint security (EDR) and network monitoring. The use of high-reputation web services as DDRs and the abuse of standard protocols like FTP for staging indicate a persistent shift toward living-off-trusted-services to maintain long-term access.
