logo

VIPERTUNNEL Python Backdoor Hidden in Fake DLL, Obfuscated Loader Chain

ID: ae9cd687-41fa-51fd-81bb-3046e640d4b8

STIX ID: report--ae9cd687-41fa-51fd-81bb-3046e640d4b8

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-04-13

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

This report analyzes VIPERTUNNEL, a sophisticated multi‑stage Python backdoor disguised as a fake DLL and loaded via a sitecustomize.py persistence mechanism; it uses layered obfuscation, strong cryptography, and an in‑memory staged loader to deploy a SOCKS5 proxy over port 443 for tunneling and exfiltration. The investigation links samples to UNC2165/EvilCorp and DragonForce ransomware activity, notes overlaps with the ShadowCoil credential‑stealer framework, and documents indicators such as scheduled tasks, file paths, and hard‑coded C2s.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.