BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

DEEP#DOOR Python Backdoor Steals Cloud Credentials

Sophisticated Python backdoor DEEP#DOOR steals cloud credentials via tunneling.

  • A stealthy Python backdoor called DEEP#DOOR uses a tunneling service for command-and-control to steal sensitive data, including cloud credentials and SSH keys.
  • The malware embeds its payload directly within the dropper script to minimize forensic traces and employs multiple anti-analysis mechanisms to evade detection.
  • Securonix researchers detail how the framework establishes persistent access through various system mechanisms, making remediation difficult.

Cybersecurity researchers from Securonix have disclosed details of a sophisticated Python-based backdoor framework called DEEP#DOOR, which was designed to harvest extensive data from compromised systems, according to a report shared with The Hacker News in late April 2026.

- Advertisement -

The attack chain begins with a batch script that disables Windows security controls and dynamically extracts an embedded Python payload. Consequently, it establishes persistence through Startup folder scripts, registry Run keys, and scheduled tasks.

This approach reduces the need for external infrastructure, thereby minimizing the forensic footprint. The malware then establishes communication with a public Rust-based tunneling service called “bore[.]pub.”

The operator can then issue commands for reverse shell access and extensive surveillance. These capabilities include keylogging, clipboard monitoring, webcam access, and ambient audio recording.

The framework also harvests credentials from web browsers, Windows Credential Manager, and major cloud platforms like AWS, Google Cloud, and Microsoft Azure. It additionally extracts SSH keys for further network compromise.

- Advertisement -

Using a public tunneling service for command-and-control blends malicious traffic with legitimate network activity. This tactic avoids embedding server details within the payload itself.

DEEP#DOOR incorporates numerous anti-analysis and defense evasion mechanisms to complicate incident response. These include sandbox detection, ETW patching, Microsoft Defender tampering, and log clearing.

It also employs a watchdog mechanism to automatically recreate removed persistence artifacts. “The resulting implant operates as a fully featured Remote Access Trojan (RAT) capable of long-term persistence, espionage, lateral movement, and post-exploitation operations within compromised environments,” Securonix said.

The researchers assessed that the initial batch script is likely distributed via traditional phishing approaches. Meanwhile, the current scale and success rate of these attacks remain unknown.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

SEC Clears Franklin Templeton to Invest in Onchain Money Fund

The SEC issued a no-action letter allowing Franklin Templeton funds to invest in its...

SharePoint CVE-2026-55040 exploited after PoC release

Threat actors are actively exploiting a critical Microsoft SharePoint vulnerability (CVE-2026-55040, CVSS 9.1) after...

Bernstein Hikes Microsoft Target to $660, Bullish on AI

Bernstein raised its Microsoft (MSFT) price target from $647 to $660, maintaining an outperform...

Bitwise: Crypto valuations could double on buybacks, burns

Bitwise CIO Matt Hougan argues crypto valuations could at least double as protocols route...

ASX shareholder seeks court approval to sue directors over blockchain failure

A shareholder is seeking court permission to sue former ASX officers and directors over...

Must Read

Top 5 Testing Tools For Blockchain Applications in 2022

Blockchain apps have been adopted popularly by some prominent industries due to its being a decentralized-designed technology. Furthermore, these apps eliminate the risks that...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading