Researchers reported a real malware campaign where attackers use Spanish-language “voucher claim” messages to trick people into running a Windows Shortcut file. After the user clicks it, the malware pulls commands from an FTP server’s welcome banner and continues downloading additional payloads, ultimately installing remote-access trojans (E4del and PINHOLE).
Key findings
- Attackers used Spanish-language voucher-claim lures to get users to run a Windows Shortcut (LNK).
- The campaign used an unusual technique: putting attacker commands in an FTP server’s welcome banner (a “dead drop resolver”).
- A multi-stage chain pulled further commands and payloads via FTP banner(s), WebDAV, and PowerShell, ultimately delivering E4del and PINHOLE RATs.
- One payload was “masquerading as Discord” (a signed Electron app).
- PINHOLE used “high-reputation platforms like Pinterest and SurveyMonkey as DDRs” and “proxy the communication through Cloudflare Workers.”
Who’s being targeted
- Commonly targeted roles: All employees, Finance, HR, Operations, IT Helpdesk.
- Attack channels: email.
- Impersonated: Voucher or rewards program (unspecified).
Awareness takeaways
- Treat unexpected “voucher/reward claim” messages as suspicious, especially if they ask you to run an attached file.
- Never run Windows Shortcut (LNK) attachments from email unless IT/security explicitly verifies them.
- Be alert to files or installers that pretend to be well-known apps (e.g., Discord) or “updates,” even if they look professional.
Red flags to watch for
- Unexpected voucher/reward claim message
- Attachment is a Windows Shortcut (.LNK) rather than a normal document
- Pressure to click/run a file to redeem a voucher
Read the video transcript
You get an email in Spanish: "Tu vale está listo, abre el archivo para reclamar tu voucher." Looks harmless, right? But that attachment is a Windows Shortcut, a .LNK. Once you run it, it secretly talks to an FTP server and reads commands hidden in the server’s welcome banner, then chains into PowerShell and WebDAV to drop remote‑access trojans like E4del and PINHOLE. Here’s the nasty twist: one payload pretends to be a polished Discord installer, and PINHOLE can even hide its traffic behind high‑reputation sites like Pinterest or SurveyMonkey and route through Cloudflare Workers. To you, it just looks like normal web traffic. Your move: if an email about a voucher or reward includes a .LNK shortcut, don’t open it, forward it to the security team and delete it.