logo

Ransomware-Linked ViperTunnel Malware Hits UK and US Businesses

ID: 2861474c-d799-5027-9209-aa4f15e9c4a9

STIX ID: report--2861474c-d799-5027-9209-aa4f15e9c4a9

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-04-14

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

A new Python backdoor named ViperTunnel has been observed in UK and US businesses; researchers report it is deployed after fake-update (SocGholish) infections, provides persistent access via a sitecustomize.py installation (path: C:\ProgramData\cp49s\Lib\sitecustomize.py), disguises its payload as b5yogiiy3c.dll, establishes a SOCKS5 proxy on port 443 to blend with normal traffic, and uses layered obfuscation (Base85, zlib, AES, ChaCha20) and PyOBFUSCATE; the activity is attributed to UNC2165/EvilCorp-linked actors and is reportedly used to support ransomware operations with signs of evolving cross-platform ambitions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.