logo

Obfuscated Loader Chain Delivers VIPERTUNNEL Backdoor via Fake DLL

ID: 5d759cd4-8208-5125-9375-94a2ac686f04

STIX ID: report--5d759cd4-8208-5125-9375-94a2ac686f04

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-04-14

Date Updated: 2026-04-14

Author: Varshini

...
...

The report details a multi-stage, Python-centric loader that abuses sitecustomize.py and a deceptive file named b5yogiiy3c.dll to execute VIPERTUNNEL, a Python SOCKS5 proxy backdoor tunneling over TCP 443. Observed during a DragonForce ransomware intrusion and linked to UNC2165/EvilCorp and former RansomHub affiliates, the campaign uses layered obfuscation (Base85, BLAKE3/SHA256/AES/ChaCha20, zlib), embeds default C2 credentials with runtime override capability, and provides huntable IOCs such as the scheduled task "523135538", pythonw.exe at C:\ProgramData\cp49s, sitecustomize.py, and the fake DLL filename.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.