logo

New Deep#Door Stealer Campaign Spills Browser Passwords, Cloud Tokens, and SSH Keys

ID: 5281e9d2-5ba5-586a-a8c6-7c875a2fbdca

STIX ID: report--5281e9d2-5ba5-586a-a8c6-7c875a2fbdca

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

Author: Varshini

...
...

Deep#Door is a Windows backdoor and credential stealer delivered by an obfuscated batch installer that writes an embedded Python implant (svc.py). The campaign disables security features, performs sandbox/VM/debugger checks, creates multiple persistence mechanisms (Startup, Run keys, scheduled tasks, optional WMI), and includes a watchdog to restore deleted artifacts. Functionally it provides keylogging, clipboard capture, screenshots, webcam/microphone access, remote command execution and broad credential theft (browser passwords, SSH keys, Windows Credential Manager, and cloud tokens), while using bore.pub and tunnel-like behaviors to hide C2 communications and frustrate blocking and attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.