New Deep#Door Stealer Campaign Spills Browser Passwords, Cloud Tokens, and SSH Keys
ID: 5281e9d2-5ba5-586a-a8c6-7c875a2fbdca
STIX ID: report--5281e9d2-5ba5-586a-a8c6-7c875a2fbdca
Feed Name: Cyber Press
Deep#Door is a Windows backdoor and credential stealer delivered by an obfuscated batch installer that writes an embedded Python implant (svc.py). The campaign disables security features, performs sandbox/VM/debugger checks, creates multiple persistence mechanisms (Startup, Run keys, scheduled tasks, optional WMI), and includes a watchdog to restore deleted artifacts. Functionally it provides keylogging, clipboard capture, screenshots, webcam/microphone access, remote command execution and broad credential theft (browser passwords, SSH keys, Windows Credential Manager, and cloud tokens), while using bore.pub and tunnel-like behaviors to hide C2 communications and frustrate blocking and attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
