FTP Banner Dead Drops: A Hunter’s Field Guide to E4del and PINHOLE

THREAT INTELLIGENCE REPORT  Prepared by   Essa Amous, CTO, RST Cloud  Reporting date   10 September 2026  Introduction  This article builds on the original research published by SOCRadar, which identified a Windows malware delivery campaign using FTP server banners as dead-drop resolvers to distribute the E4del and PINHOLE remote access trojans.Rather than embedding a fixed payload location…

TencShell and Gshell

TencShell and Gshell

THREAT INTELLIGENCE REPORT  Prepared by   Alexander Gould, CTI Strategist, RST Cloud  Reporting date   17 August 2026  Collection   Scan-derived figures are as at 10 August 2026 Active infrastructure and an exposed exploitation chain Summary  Suspected China-linked operators are running an intrusion campaign against government bodies in Taiwan, Thailand, Afghanistan and the United States, and against billing…

contagious interview fleet

An Undocumented OtterCookie-Lineage Build and Its Invisible C2 Fleet

How one stage-3 payload led to nine OtterCookie-related hosts, three server fingerprints, and a Contagious Interview infrastructure fleet sitting at zero detections. Author: Yury Sergeev, RST Cloud Published: 15 August 2026 Summary A client shared a single stage-3 payload from a DPRK-nexus Contagious Interview delivery chain. Deobfuscating it yielded more than a capability list: it exposed the…