Deep#Door Python Backdoor Evades Detection On Windows
ID: f620ded5-bf7c-5f8e-aae0-c68caf1f3eaf
STIX ID: report--f620ded5-bf7c-5f8e-aae0-c68caf1f3eaf
Feed Name: Infosecurity Magazine (News)
Deep#Door is a stealthy, Python-based Windows backdoor deployed via a heavily obfuscated batch loader that embeds its payload to avoid network detection. The implant uses multiple persistence mechanisms (startup items, registry run keys, scheduled tasks, optional WMI subscriptions), disables security controls, performs anti-analysis checks, and communicates using a public TCP tunneling service for C2. Capabilities include keylogging, screenshots, microphone recording, browser credential and SSH/cloud token theft, and optional destructive functions (system crashes and boot record overwrites), enabling both long-term espionage and potential disruption.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
