VIPERTUNNEL Python Backdoor Hidden in Fake DLL, Obfuscated Loader Chain
ID: ae9cd687-41fa-51fd-81bb-3046e640d4b8
STIX ID: report--ae9cd687-41fa-51fd-81bb-3046e640d4b8
Feed Name: GBHackers
This report analyzes VIPERTUNNEL, a sophisticated multi‑stage Python backdoor disguised as a fake DLL and loaded via a sitecustomize.py persistence mechanism; it uses layered obfuscation, strong cryptography, and an in‑memory staged loader to deploy a SOCKS5 proxy over port 443 for tunneling and exfiltration. The investigation links samples to UNC2165/EvilCorp and DragonForce ransomware activity, notes overlaps with the ShadowCoil credential‑stealer framework, and documents indicators such as scheduled tasks, file paths, and hard‑coded C2s.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
