logo

VIPERTUNNEL Hijacks Python for Stealthy Ransomware Access

ID: a72afab4-47ec-5651-bd8c-d53e36c4f3e4

STIX ID: report--a72afab4-47ec-5651-bd8c-d53e36c4f3e4

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-04-16

Date Updated: 2026-04-23

Author: Ddos

...
...

InfoGuard's analysis uncovers VIPERTUNNEL, a modular Python backdoor used alongside DragonForce ransomware that persists via C:\ProgramData\cp49s\Lib\sitecustomize.py, uses Base85 encoding and control-flow flattening to evade detection, and establishes a SOCKS5 tunnel to hardcoded C2 over port 443; linked actors include UNC2165 and EvilCorp, and related ShadowCoil samples suggest the obfuscation framework may be extended to Linux.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.