logo

Deep#Door Python Backdoor Evades Detection On Windows

ID: f620ded5-bf7c-5f8e-aae0-c68caf1f3eaf

STIX ID: report--f620ded5-bf7c-5f8e-aae0-c68caf1f3eaf

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

...
...

Deep#Door is a stealthy, Python-based Windows backdoor deployed via a heavily obfuscated batch loader that embeds its payload to avoid network detection. The implant uses multiple persistence mechanisms (startup items, registry run keys, scheduled tasks, optional WMI subscriptions), disables security controls, performs anti-analysis checks, and communicates using a public TCP tunneling service for C2. Capabilities include keylogging, screenshots, microphone recording, browser credential and SSH/cloud token theft, and optional destructive functions (system crashes and boot record overwrites), enabling both long-term espionage and potential disruption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.