Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE.

While threat actors are known to abuse legitimate services to point to additional command-and-control (C2) infrastructure and blend in with regular network traffic, the development marks the first time this unusual technique has been spotted in the wild.

An FTP banner is a welcome message or text string that an FTP server sends to a client immediately upon connection. The mechanism allows "malware stagers to fetch commands directly from the protocol's initial response," SOCRadar said in a technical report. The modus operandi was first highlighted by the MalwareHunterTeam early last month.

However, it's worth noting that the method is a lot less stealthy than traditional web-based DDRs, as security controls are likely to flag FTP connections to unknown servers as anomalous.

In one case, the attack chain involves using Spanish-language lures related to voucher claims to deceive unwitting users into executing a Windows Shortcut (LNK), which then retrieves the next-stage command from an FTP banner. The command connects to a WebDAV server to download and execute a DLL export via "rundll32.exe" using conhost.