1. Basic Information
Article Title: FTP Banners: The New Dead Drop Resolver Delivering Novel RATs
Publisher: SOCRadar Threat Research Unit
Publication Date: 2026-08-21
Update Date: None
1. Basic Information Article Title: FTP Banners: The New Dead Drop Resolver Delivering...
1. Basic Information
Article Title: FTP Banners: The New Dead Drop Resolver Delivering Novel RATs
Publisher: SOCRadar Threat Research Unit
Publication Date: 2026-08-21
Update Date: None

SOCRadar details E4del and PINHOLE RAT campaigns using FTP banners as dead drop resolvers to fetch commands and C2 details.

Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del…

DOUBLECUP hides malware stages in cached PNG files, then uses ClickFix commands to deliver CountLoader variants and the…

Rapid7 pulls 1,048 files from an exposed server, linking an LLM-assisted phishing pipeline to a live WebDAV campaign targeting…

DOUBLECUP: ClickFix Loader-as-a-Service Restoring Fileless Payload from PNG in Browser...

We found EtherRAT malware being distributed by a website with a strange homepage. Following the trail, we discovered a vast…