Attackers Hide Malware Commands Inside FTP Server Banners
Researchers have uncovered a malware campaign that abuses FTP server banners — the plain-text greeting messages servers display when a client connects — as a covert channel for delivering attack commands. Threat actors are using this trick to distribute two previously unseen remote access trojans, dubbed E4del and PINHOLE, onto Windows machines.
Because FTP banners are typically ignored by security tools as harmless metadata, hiding encoded instructions inside them lets attackers slip commands past network monitoring that focuses on file transfers or payloads rather than protocol handshake text. Once triggered, the malware can give attackers remote access and control over infected systems.
The campaign highlights how attackers continue to find overlooked corners of legacy protocols to stage intrusions, especially in environments where FTP is still exposed to the internet.