Voucher Lure Drops RAT via FTP Banner Tricks

The Hacker News · High sophistication
Last updated August 25, 2026

Researchers reported a real malware campaign where attackers use Spanish-language “voucher claim” messages to trick people into running a Windows Shortcut file. After the user clicks it, the malware pulls commands from an FTP server’s welcome banner and continues downloading additional payloads, ultimately installing remote-access trojans (E4del and PINHOLE).

Key findings

  • Attackers used Spanish-language voucher-claim lures to get users to run a Windows Shortcut (LNK).
  • The campaign used an unusual technique: putting attacker commands in an FTP server’s welcome banner (a “dead drop resolver”).
  • A multi-stage chain pulled further commands and payloads via FTP banner(s), WebDAV, and PowerShell, ultimately delivering E4del and PINHOLE RATs.
  • One payload was “masquerading as Discord” (a signed Electron app).
  • PINHOLE used “high-reputation platforms like Pinterest and SurveyMonkey as DDRs” and “proxy the communication through Cloudflare Workers.”

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, HR, Operations, IT Helpdesk.
  • Attack channels: email.
  • Impersonated: Voucher or rewards program (unspecified).

Awareness takeaways

  • Treat unexpected “voucher/reward claim” messages as suspicious, especially if they ask you to run an attached file.
  • Never run Windows Shortcut (LNK) attachments from email unless IT/security explicitly verifies them.
  • Be alert to files or installers that pretend to be well-known apps (e.g., Discord) or “updates,” even if they look professional.

Red flags to watch for

  • Unexpected voucher/reward claim message
  • Attachment is a Windows Shortcut (.LNK) rather than a normal document
  • Pressure to click/run a file to redeem a voucher
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You get an email in Spanish: "Tu vale está listo, abre el archivo para reclamar tu voucher." Looks harmless, right? But that attachment is a Windows Shortcut, a .LNK. Once you run it, it secretly talks to an FTP server and reads commands hidden in the server’s welcome banner, then chains into PowerShell and WebDAV to drop remote‑access trojans like E4del and PINHOLE. Here’s the nasty twist: one payload pretends to be a polished Discord installer, and PINHOLE can even hide its traffic behind high‑reputation sites like Pinterest or SurveyMonkey and route through Cloudflare Workers. To you, it just looks like normal web traffic. Your move: if an email about a voucher or reward includes a .LNK shortcut, don’t open it, forward it to the security team and delete it.

Similar attacks

Larva-24009 Lures Firms With Fake Doc Attachments

Larva-24009 Lures Firms With Fake Doc Attachments

AhnLab reports Larva-24009 has continued phishing campaigns through 2026, sending emails that trick employees into opening fake “document” attachments that are actually shortcut (LNK) files. When opened, the attachment runs hidden PowerShell commands, shows a decoy document, and silently downloads…

August 3, 2026
Phish Drops MSP360, Then Installs ScreenConnect

Phish Drops MSP360, Then Installs ScreenConnect

Microsoft reported real phishing campaigns that trick users into running a legitimate MSP360 remote-management installer disguised as meeting invites, PDFs, and software updates. After MSP360 is installed, attackers use it to silently install ScreenConnect as a second remote-access path, then use…

September 30, 2026
Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Researchers described an active phishing campaign that tricks people with fake Adobe/Zoom update and “document review” themes to install the legitimate ScreenConnect remote-access tool. Once installed, attackers get persistent remote control of the victim’s computer while blending in as normal IT…

August 4, 2026
Fake LastPass GitHub Drops Rapuncel Stealer

Fake LastPass GitHub Drops Rapuncel Stealer

Attackers impersonated LastPass on GitHub and tricked people searching for the “LastPass Authenticator download” into installing a fake installer. The infection chain used a Microsoft-signed driver to disable many security tools, then deployed an infostealer that stole passwords, crypto wallets,…

September 23, 2026
Fake AI Trading Bot Steals Crypto Wallet Passwords

Fake AI Trading Bot Steals Crypto Wallet Passwords

Researchers observed real campaigns where a fake “AI crypto trading agent” website tricked victims into downloading malware that silently replaces browser wallet extensions and steals the wallet password when it’s typed. The same reporting also describes invoice emails using QR codes to push…

September 17, 2026
Star Blizzard’s RedFlick Phish Uses VHDX Trap

Star Blizzard’s RedFlick Phish Uses VHDX Trap

Microsoft reports real-world Star Blizzard phishing campaigns where victims who engage with an initial email receive a follow-up message containing a password-protected ZIP/RAR attachment. The attachment chain hides a malicious shortcut disguised as a PDF, opening a decoy file while quietly…

September 30, 2026