Hackers Hide Malware Instructions in FTP Server Greetings
A quiet trick spotted by SOCRadar uses FTP welcome messages to smuggle commands onto Windows machines, dropping two new remote-control tools called E4del and PINHOLE.

Key points
- Researchers at SOCRadar found attackers hiding commands inside FTP server banners, the short greeting text a server shows when a computer connects, to deliver malware to Windows PCs.
- The campaign has been running since early July 2026 and was still active in August 2026, with new servers observed as recently as last month.
- Two previously unknown remote access tools were dropped: E4del, disguised as the Discord chat app, and PINHOLE, which pulls its instructions from Pinterest pins and SurveyMonkey surveys.
- Victims are first tricked by a phishing email carrying a ZIP file with a booby-trapped shortcut (.LNK) inside.
- PINHOLE had logged only 11 executions at the time of analysis, suggesting the campaign is still small and early-stage.
Here is a novel one. Criminals are stuffing attack instructions into the greeting text that FTP servers show when a computer connects. That greeting, called a banner, is meant to say hello. In this campaign it says: run this.
The technique was flagged by threat intelligence firm SOCRadar and first reported by BleepingComputer. It's a fresh spin on a dead-drop resolver, where malware fetches its orders from somewhere ordinary so the traffic looks unremarkable. We covered that technique for the first time on 21 August 2026; it's now showing up in infrastructure that didn't exist when we filed that piece.
How does the attack actually work?
It starts with a phishing email carrying a ZIP file. Inside is a Windows shortcut file, the icon type with the .LNK ending that normally points to a program. Open it and the shortcut quietly reaches out to an FTP server, reads the greeting banner, and pulls a PowerShell script out of that text. PowerShell is the scripting tool built into every modern Windows PC, and it's a favourite of attackers because the system already trusts it.
From there the script installs one of two remote access trojans, RATs, tools that let an outsider control the machine as if they were sitting at it.
What are E4del and PINHOLE?
These are the two new remote-control programs the researchers pulled apart. E4del pretends to be Discord and is built on Node.js wrapped inside a signed Electron application, meaning it carries a digital signature that makes Windows less suspicious of it. It can open a shell, take screenshots, stream the desktop live over WebSockets, and pull down more malware on demand.
PINHOLE's sneakier. It fetches its command-and-control settings from Pinterest pins and SurveyMonkey questions, so blocking one server doesn't kill it. Only a 4KB slice of the payload sits in memory at any moment, and the final code injects into a suspended Windows process called ApplicationFrameHost.exe via Early Bird APC injection, a technique for slipping code into a process before it fully starts. In plain terms: it hides inside a program Windows already trusts. It supports 14 commands, including stealing passwords saved in browsers.
| Malware | Disguise | Notable capability | Delivery |
|---|---|---|---|
| E4del | Fake Discord app | Live desktop streaming | PowerShell from FTP banner |
| PINHOLE | None, memory-only | Browser credential theft | PowerShell from FTP banner |
Should ordinary people be worried?
Not directly, but the entry point is familiar: a phishing email with a ZIP attachment. Don't open unexpected files, even when the sender looks legitimate. A suddenly sluggish work laptop or browser credentials that stop working are worth reporting to your IT team immediately.
SOCRadar notes the FTP trick is actually less stealthy than hiding commands on GitHub or YouTube, because a company laptop connecting to a random FTP server tends to stand out on a network log. The failure mode here is defenders who watch web traffic closely and treat FTP as legacy noise worth ignoring. One thing the post-mortem will say: nobody was watching the banners.
If your egress rules still allow outbound FTP to arbitrary hosts, that's a monitoring gap worth closing this week.



