logo

The Self-Parsing Ghost: Inside Deep#Door’s Stealthy Python Backdoor

ID: 5ca1d47b-8314-5d0e-bc53-c303b92bb90c

STIX ID: report--5ca1d47b-8314-5d0e-bc53-c303b92bb90c

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Ddos

...
...

Securonix Threat Research describes Deep#Door, a sophisticated Python-based RAT embedded inside a single obfuscated batch dropper that reconstructs and installs a stealthy implant. The malware provides real-time surveillance (keylogging, screen capture, webcam/mic access), credential and token theft (browsers, SSH, cloud tokens), defense-evasion (AMSI patching, disabling Defender), persistence mechanisms, and destructive post-exploitation features (MBR overwrite, BSOD). It avoids hardcoded C2 by using the public TCP tunneling service bore.pub and performs aggressive scanning to discover active tunnels, increasing stealth and resilience against takedown efforts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.