The SOCRadar Threat Research Unit has unveiled a delivery technique that they haven’t seen documented before: threat actors are hiding staging commands inside FTP server banners, the greeting text a server sends when you connect to port 21.
Key details
- Threat actors are hiding malware staging commands inside FTP server banners – the greeting text a server returns on port 21. A shortcut file connects, reads the banner, executes what’s in it. Nothing malicious in the file itself.
- This is a dead drop resolver on a protocol nobody inspects for content. The technique has not been documented before.
- Live since early July 2026 and still operational.
Full research can be read here: https://socradar.io/blog/ftp-banners-new-dead-drop-resolver-rats/
Related
This entry was posted on August 21, 2026 at 12:13 pm and is filed under Commentary with tags SOCRadar. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
FTP Banners: The New Dead Drop Resolver Delivering Novel RATs
The SOCRadar Threat Research Unit has unveiled a delivery technique that they haven’t seen documented before: threat actors are hiding staging commands inside FTP server banners, the greeting text a server sends when you connect to port 21.
Key details
Full research can be read here: https://socradar.io/blog/ftp-banners-new-dead-drop-resolver-rats/
Share this:
Like this:
Related
This entry was posted on August 21, 2026 at 12:13 pm and is filed under Commentary with tags SOCRadar. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.