logo

New Deep#Door RAT uses stealth and persistence to target Windows

ID: 65cc68fa-1789-5792-b2c3-c6dd513af687

STIX ID: report--65cc68fa-1789-5792-b2c3-c6dd513af687

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2026-05-02

Date Updated: 2026-05-02

Author: Pierluigi Paganini

...
...

Security researchers at Securonix uncovered the Deep#Door campaign: a stealthy Python RAT embedded inside a self-parsing batch dropper that disables Windows defenses, uses multiple persistence mechanisms and a watchdog to survive remediation, performs credential and data theft (and can be destructive), and communicates covertly via the public TCP tunneling service bore.pub, complicating detection and attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.