This is a clever tradecraft evolution. Using FTP banners as dead drop resolvers (DDRs) is a low-and-slow technique that bypasses traditional DNS and HTTP-based C2 detection.
Technical Breakdown
- TTPs (MITRE):
- T1573.001 (Encrypted Channel: Symmetric Cryptography): The RATs use AES-encrypted payloads.
- T1102 (Web Service): Abusing FTP banner text as a covert channel.
- T1071.002 (Application Layer Protocol: File Transfer Protocols): C2 communication over FTP.
- IOCs:
- Malware: E4del (backdoor), PINHOLE (RAT).
- Delivery: Malicious FTP banners containing AES-encrypted blobs that resolve to the next stage C2 IP.
- C2: The banner itself is not the C2; it contains an encrypted pointer to the actual C2 server.
- Affected Systems: Any Windows environment where users can initiate outbound FTP connections (common in media, logistics, and dev shops).
Defense
- Detection: Monitor for anomalous FTP banner lengths or non-standard ASCII characters in banner responses. Correlate outbound FTP connections from workstations (not just servers) to external IPs.
- Mitigation: Block outbound FTP (port 21) from user workstations at the firewall. If FTP is required, restrict it to specific, monitored jump boxes.
Source: https://thehackernews.com/2026/08/e4del-and-pinhole-rats-turn-ftp-banners.html
Source: r/SecOpsDaily · by /u/falconupkid