Back to all lessons
Awareness Lessons
2 months ago

FTP Banners Weaponized as Covert Command Channels for New RAT Malware

Attackers have devised a novel technique using FTP server welcome banners as covert dead drop resolvers, embedding malware commands in a channel that most security tools do not scrutinize. Users are lured via social engineering — such as fake voucher offers — into executing malicious code that silently contacts FTP servers and retrieves instructions, bypassing traditional detection mechanisms. This matters because it exploits a blind spot in conventional network monitoring, where FTP banner traffic is rarely inspected for command-and-control (C2) activity. The combination of a novel C2 channel with proven social engineering tactics significantly lowers the barrier to successful compromise, even in environments with mature defenses.

Tactical Insight

Immediate actions

  • Block or restrict outbound FTP connections (port 21) at the perimeter firewall unless explicitly required by business operations.
  • Deploy endpoint detection and response (EDR) tools configured to alert on unusual process executions triggered by user-facing documents or browser downloads.
  • Conduct emergency user awareness communications warning staff not to click unsolicited voucher, coupon, or prize-claim links.

Detection measures

  • Configure network monitoring and SIEM rules to inspect and alert on FTP banner/welcome message content for anomalous or encoded strings.
  • Enable deep packet inspection (DPI) on all FTP traffic to capture and log banner exchanges for forensic review.
  • Hunt for LOLBins (living-off-the-land binaries) and unusual parent-child process relationships that may indicate RAT execution.

Long-term improvements

  • Implement a Zero Trust network architecture that explicitly denies all non-approved outbound protocols and inspects approved ones.
  • Establish a regular security awareness training program that includes simulated social engineering scenarios mimicking fake vouchers and reward lures.
  • Develop and maintain a protocol allowlist policy, ensuring non-standard or legacy protocols like FTP are reviewed quarterly for necessity and risk.