BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

DEEP#DOOR Python Backdoor Steals Cloud Credentials

Sophisticated Python backdoor DEEP#DOOR steals cloud credentials via tunneling.

  • A stealthy Python backdoor called DEEP#DOOR uses a tunneling service for command-and-control to steal sensitive data, including cloud credentials and SSH keys.
  • The malware embeds its payload directly within the dropper script to minimize forensic traces and employs multiple anti-analysis mechanisms to evade detection.
  • Securonix researchers detail how the framework establishes persistent access through various system mechanisms, making remediation difficult.

Cybersecurity researchers from Securonix have disclosed details of a sophisticated Python-based backdoor framework called DEEP#DOOR, which was designed to harvest extensive data from compromised systems, according to a report shared with The Hacker News in late April 2026.

- Advertisement -

The attack chain begins with a batch script that disables Windows security controls and dynamically extracts an embedded Python payload. Consequently, it establishes persistence through Startup folder scripts, registry Run keys, and scheduled tasks.

This approach reduces the need for external infrastructure, thereby minimizing the forensic footprint. The malware then establishes communication with a public Rust-based tunneling service called “bore[.]pub.”

The operator can then issue commands for reverse shell access and extensive surveillance. These capabilities include keylogging, clipboard monitoring, webcam access, and ambient audio recording.

The framework also harvests credentials from web browsers, Windows Credential Manager, and major cloud platforms like AWS, Google Cloud, and Microsoft Azure. It additionally extracts SSH keys for further network compromise.

- Advertisement -

Using a public tunneling service for command-and-control blends malicious traffic with legitimate network activity. This tactic avoids embedding server details within the payload itself.

DEEP#DOOR incorporates numerous anti-analysis and defense evasion mechanisms to complicate incident response. These include sandbox detection, ETW patching, Microsoft Defender tampering, and log clearing.

It also employs a watchdog mechanism to automatically recreate removed persistence artifacts. “The resulting implant operates as a fully featured Remote Access Trojan (RAT) capable of long-term persistence, espionage, lateral movement, and post-exploitation operations within compromised environments,” Securonix said.

The researchers assessed that the initial batch script is likely distributed via traditional phishing approaches. Meanwhile, the current scale and success rate of these attacks remain unknown.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

SEC’s ‘Crypto Mom’ Peirce Joins Regent Law Faculty

Longtime SEC Commissioner Hester Peirce, known as "Crypto Mom," will leave the regulator to...

Microsoft unveils AI security tools RAMPART, Clarity

Microsoft has launched two new open-source security tools, RAMPART and Clarity, designed for AI...

OpenAI Readies IPO Filing, Targets September Market Debut

OpenAI is preparing to file for its landmark IPO in the coming days or...

OpenAI IPO planned for September: Wall Street Journal

OpenAI is reportedly targeting a September IPO with Goldman Sachs and Morgan Stanley as...

Institutional Investors Boost MSTR Positions Amid Bitcoin Rally

Thirteen of Strategy's 15 largest institutional shareholders increased their stakes in the company during...

Must Read

9 Best Books On Ethereum And Blockchain Technology

QUICK LINKSHow to Choose Your First Blockchain Book: A Simple Framework1. Define Your Goal: Are you looking to Build, Invest, or Understand?2. Assess Your...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading