FTP Banners: The New Dead Drop Resolver Delivering Novel RATs

The SOCRadar Threat Research Unit has unveiled a delivery technique that they haven’t seen documented before: threat actors are hiding staging commands inside FTP server banners, the greeting text a server sends when you connect to port 21.

Key details

  • Threat actors are hiding malware staging commands inside FTP server banners – the greeting text a server returns on port 21. A shortcut file connects, reads the banner, executes what’s in it. Nothing malicious in the file itself.
  • This is a dead drop resolver on a protocol nobody inspects for content. The technique has not been documented before.
  • Live since early July 2026 and still operational.

Full research can be read here: https://socradar.io/blog/ftp-banners-new-dead-drop-resolver-rats/ 

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading