Threat Intelligence

New RATs Hide Commands Inside FTP Server Banners

The Hacker News · 25 Aug 2026
Key Takeaway Ensure your security monitoring tools inspect unusual outbound connections and traffic patterns, not just known malicious IP addresses, since attackers increasingly hide commands within legitimate-looking network services.

Security researchers have identified a novel attack technique where cybercriminals hide command-and-control instructions inside FTP server banners, the small text messages that appear when connecting to an FTP service. This method, known as a 'dead drop resolver,' allows attackers to deliver instructions to infected computers without directly contacting their own servers, making the malicious traffic look like ordinary network activity.

The campaign has been linked to two previously undocumented remote access trojans (RATs) named E4del and PINHOLE. These tools give attackers the ability to remotely control infected systems, potentially stealing data or deploying further malware. By using publicly accessible FTP banners rather than dedicated command servers, attackers make it harder for security tools to detect the malicious communication, since the traffic can blend in with legitimate internet services.

While the full scope of the campaign and its targets remain under investigation, the use of legitimate infrastructure to mask malicious activity is a growing trend among cybercriminals. This technique highlights how attackers continue to evolve methods to evade detection, and businesses should be aware that not all suspicious activity will look obviously malicious.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.