Hackers are using a new trick that hides malware commands inside FTP server greeting messages to infect Windows systems with two newly identified remote access trojans, E4del and PINHOLE. According to SOCRadar and MalwareHunterTeam, the campaign has been active since at least July 2026 and starts with ZIP archives containing malicious shortcut (.LNK) files, likely delivered by phishing. E4del is a Node.js remote access trojan packaged in a signed Electron app posing as Discord, while PINHOLE pulls command-and-control settings from Pinterest and SurveyMonkey and uses process injection to hide on infected machines.
Why it matters: This is an active Windows malware campaign using a less common delivery channel that may evade simple web-focused detections. Organizations should hunt for suspicious FTP connections, block or inspect LNK-based phishing payloads, and review the published indicators of compromise now.
Bill Toulas
2026.08.21
100% relevant
This article appears to be the first clear reporting entry on this specific campaign and its malware families, including the FTP-banner dead-drop technique and the E4del and PINHOLE implants.
← Back to all stories