FTP Banners Weaponized as Covert Command Channels for New RAT Malware
Attackers have devised a novel technique using FTP server welcome banners as covert dead drop resolvers, embedding malware commands in a channel that most security tools do not scrutinize. Users are lured via social engineering — such as fake voucher offers — into executing malicious code that silently contacts FTP servers and retrieves instructions, bypassing traditional detection mechanisms. This matters because it exploits a blind spot in conventional network monitoring, where FTP banner traffic is rarely inspected for command-and-control (C2) activity. The combination of a novel C2 channel with proven social engineering tactics significantly lowers the barrier to successful compromise, even in environments with mature defenses.
Tactical Insight
Immediate actions
- Block or restrict outbound FTP connections (port 21) at the perimeter firewall unless explicitly required by business operations.
- Deploy endpoint detection and response (EDR) tools configured to alert on unusual process executions triggered by user-facing documents or browser downloads.
- Conduct emergency user awareness communications warning staff not to click unsolicited voucher, coupon, or prize-claim links.
Detection measures
- Configure network monitoring and SIEM rules to inspect and alert on FTP banner/welcome message content for anomalous or encoded strings.
- Enable deep packet inspection (DPI) on all FTP traffic to capture and log banner exchanges for forensic review.
- Hunt for LOLBins (living-off-the-land binaries) and unusual parent-child process relationships that may indicate RAT execution.
Long-term improvements
- Implement a Zero Trust network architecture that explicitly denies all non-approved outbound protocols and inspects approved ones.
- Establish a regular security awareness training program that includes simulated social engineering scenarios mimicking fake vouchers and reward lures.
- Develop and maintain a protocol allowlist policy, ensuring non-standard or legacy protocols like FTP are reviewed quarterly for necessity and risk.