THREATOPS
THREAT OPSThreat News › FTP Banners: The New Dead Drop Resolver Delivering Novel RATs

FTP Banners: The New Dead Drop Resolver Delivering Novel RATs

medsocradar_blogPublished 2026-08-21

<h1>FTP Banners: The New Dead Drop Resolver Delivering Novel RATs</h1> <p><em>STRU found <a href="https://socradar.io/glossary/threat-actors/">threat actors</a> using FTP banners as Dead Drop Resolvers – legitimate services or protocols abused to host C2 addresses and commands, so the stager never carries them itself. Live since early July 2026 and still active. The infrastructure led to two previ

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://socradar.io/blog/ftp-banners-new-dead-drop-resolver-rats/