The Self-Parsing Ghost: Inside Deep#Door’s Stealthy Python Backdoor
ID: 5ca1d47b-8314-5d0e-bc53-c303b92bb90c
STIX ID: report--5ca1d47b-8314-5d0e-bc53-c303b92bb90c
Feed Name: securityonline.info
Securonix Threat Research describes Deep#Door, a sophisticated Python-based RAT embedded inside a single obfuscated batch dropper that reconstructs and installs a stealthy implant. The malware provides real-time surveillance (keylogging, screen capture, webcam/mic access), credential and token theft (browsers, SSH, cloud tokens), defense-evasion (AMSI patching, disabling Defender), persistence mechanisms, and destructive post-exploitation features (MBR overwrite, BSOD). It avoids hardcoded C2 by using the public TCP tunneling service bore.pub and performs aggressive scanning to discover active tunnels, increasing stealth and resilience against takedown efforts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
