The New Malware Trick Hidden Inside FTP Greetings. Hackers have discovered a new way to hide malware in a place that nobody had even considered checking.
FTP servers are crucial for the internet. FTP stands for File Transfer Protocol, and it’s one of the oldest ways that PCs share files with each other over the internet. When you connect to an FTP server, it sends you a greeting, almost welcoming you to the server. This greeting is called an FTP banner. Usually, these are harmless, comprising little more than a text message confirming a successful connection. And it’s this simplicity which the hackers are exploiting.
Hidden Instructions in the Handshake
Two new malware programs called E4del and PINHOLE have been uncovered by security researchers. As well as being new strains of malware, they also do something which hasn’t been seen before. Instead of fetching their commands from remote servers, they pull them directly from FTP banners. Exploits of this nature are rare, and most security software doesn’t even search for it. This means it’s highly effective at covering its tracks.
As with most modern cyber-attacks – with statistics showing 98% involvement – social engineering is at the heart of E4del and PINHOLE. One version of the attack involves victims receiving what appears to be a Spanish-language voucher. Clicking on this offer runs a disguised shortcut file on their PC. This shortcut establishes contact with an FTP server, reads the banner, and acts on the hidden instructions.
E4del disguises itself as popular chat app Discord and is indistinguishable from the genuine app. Once established and running, E4del starts taking screenshots, streams your desktop to the attackers, downloads further malware, and opens a back door to take remote control of your PC.
While E4del is certainly sophisticated, PINHOLE takes things to a new level. Using trusted websites such as Pinterest and SurveyMonkey, it masks its activities to look like everyday browsing traffic. It also goes through six separate unpacking stages before it activates, making it less likely to be detected by antivirus software.
What Smart Users Do Differently
E4del and PINHOLE are new and sophisticated, but they still use old-fashioned methods to breach your PC in the first place. Accordingly, staying safe is relatively simple. Here are Ophtek’s three top tips to reduce your risk.
- Always Be Suspicious of Unsolicited Files: If you receive unexpected emails or messages containing files, this should always ring alarm bells. Generally, social engineering such as this will also involve a sense of urgency, so always take a second and evaluate.
- Keep Your Antivirus Up to Date: E4del and PINHOLE both do their best to evade detection by security software. Therefore, the best way to limit this risk is by ensuring your antivirus software is up to date – this gives them the best chance of catching malware before it takes hold.
- Be Wary of Which Apps You’re Using: With E4del cleverly disguising itself as Discord, you need to make sure you always download software from official sources. If you ever notice anything slightly unusual about the way an app is behaving, check in with your IT team to give it a closer look.
For more ways to secure and optimize your business technology, contact your local IT professionals.




