logo

New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials

ID: 81c4e0e6-bf3d-5c2f-b89b-13d4d424569a

STIX ID: report--81c4e0e6-bf3d-5c2f-b89b-13d4d424569a

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: [email protected] (The Hacker News)

...
...

Securonix researchers disclosed DEEP#DOOR, a stealthy Python-based backdoor/RAT that embeds its implant in a dropper, disables Windows security controls, establishes multi-mechanism persistence, and communicates over the public tunneling service bore.pub to enable remote command execution, system reconnaissance, keylogging, credential and cloud-credential theft, and extensive surveillance, while employing numerous anti-analysis and telemetry tampering techniques; observed usage appears limited and somewhat targeted with no evidence of large-scale campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.