Deep#Door Stealer Harvests Browser Passwords, Cloud Tokens, SSH Keys, and Wi-Fi Credentials
ID: af80c3f2-df60-569f-95cb-01741c0c1af6
STIX ID: report--af80c3f2-df60-569f-95cb-01741c0c1af6
Feed Name: cybersecurityNews.com
DEEP#DOOR is a newly identified Python-based Windows backdoor deployed via an obfuscated batch script that embeds a self-contained Python RAT; it achieves persistence (Startup folder, Registry Run keys, Scheduled Tasks, WMI), disables/patches defenses (SmartScreen, AMSI, ETW, Windows Defender tampering), and exfiltrates credentials from browsers, cloud configs, SSH keys, Wi‑Fi and environment variables while providing remote access via TCP tunneling — combining strong evasion, credential theft, and remote-control capabilities that enable extended access and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
