New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials
ID: 81c4e0e6-bf3d-5c2f-b89b-13d4d424569a
STIX ID: report--81c4e0e6-bf3d-5c2f-b89b-13d4d424569a
Feed Name: The Hacker News
Securonix researchers disclosed DEEP#DOOR, a stealthy Python-based backdoor/RAT that embeds its implant in a dropper, disables Windows security controls, establishes multi-mechanism persistence, and communicates over the public tunneling service bore.pub to enable remote command execution, system reconnaissance, keylogging, credential and cloud-credential theft, and extensive surveillance, while employing numerous anti-analysis and telemetry tampering techniques; observed usage appears limited and somewhat targeted with no evidence of large-scale campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
