New RATs Hide Commands Inside FTP Server Banners
Security researchers have identified a novel attack technique where cybercriminals hide command-and-control instructions inside FTP server banners, the small text messages that appear when connecting to an FTP service. This method, known as a 'dead drop resolver,' allows attackers to deliver instructions to infected computers without directly contacting their own servers, making the malicious traffic look like ordinary network activity.
The campaign has been linked to two previously undocumented remote access trojans (RATs) named E4del and PINHOLE. These tools give attackers the ability to remotely control infected systems, potentially stealing data or deploying further malware. By using publicly accessible FTP banners rather than dedicated command servers, attackers make it harder for security tools to detect the malicious communication, since the traffic can blend in with legitimate internet services.
While the full scope of the campaign and its targets remain under investigation, the use of legitimate infrastructure to mask malicious activity is a growing trend among cybercriminals. This technique highlights how attackers continue to evolve methods to evade detection, and businesses should be aware that not all suspicious activity will look obviously malicious.