Obfuscated Loader Chain Delivers VIPERTUNNEL Backdoor via Fake DLL
ID: 5d759cd4-8208-5125-9375-94a2ac686f04
STIX ID: report--5d759cd4-8208-5125-9375-94a2ac686f04
Feed Name: Cyber Press
The report details a multi-stage, Python-centric loader that abuses sitecustomize.py and a deceptive file named b5yogiiy3c.dll to execute VIPERTUNNEL, a Python SOCKS5 proxy backdoor tunneling over TCP 443. Observed during a DragonForce ransomware intrusion and linked to UNC2165/EvilCorp and former RansomHub affiliates, the campaign uses layered obfuscation (Base85, BLAKE3/SHA256/AES/ChaCha20, zlib), embeds default C2 credentials with runtime override capability, and provides huntable IOCs such as the scheduled task "523135538", pythonw.exe at C:\ProgramData\cp49s, sitecustomize.py, and the fake DLL filename.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
