BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

DEEP#DOOR Python Backdoor Steals Cloud Credentials

Sophisticated Python backdoor DEEP#DOOR steals cloud credentials via tunneling.

  • A stealthy Python backdoor called DEEP#DOOR uses a tunneling service for command-and-control to steal sensitive data, including cloud credentials and SSH keys.
  • The malware embeds its payload directly within the dropper script to minimize forensic traces and employs multiple anti-analysis mechanisms to evade detection.
  • Securonix researchers detail how the framework establishes persistent access through various system mechanisms, making remediation difficult.

Cybersecurity researchers from Securonix have disclosed details of a sophisticated Python-based backdoor framework called DEEP#DOOR, which was designed to harvest extensive data from compromised systems, according to a report shared with The Hacker News in late April 2026.

- Advertisement -

The attack chain begins with a batch script that disables Windows security controls and dynamically extracts an embedded Python payload. Consequently, it establishes persistence through Startup folder scripts, registry Run keys, and scheduled tasks.

This approach reduces the need for external infrastructure, thereby minimizing the forensic footprint. The malware then establishes communication with a public Rust-based tunneling service called “bore[.]pub.”

The operator can then issue commands for reverse shell access and extensive surveillance. These capabilities include keylogging, clipboard monitoring, webcam access, and ambient audio recording.

The framework also harvests credentials from web browsers, Windows Credential Manager, and major cloud platforms like AWS, Google Cloud, and Microsoft Azure. It additionally extracts SSH keys for further network compromise.

- Advertisement -

Using a public tunneling service for command-and-control blends malicious traffic with legitimate network activity. This tactic avoids embedding server details within the payload itself.

DEEP#DOOR incorporates numerous anti-analysis and defense evasion mechanisms to complicate incident response. These include sandbox detection, ETW patching, Microsoft Defender tampering, and log clearing.

It also employs a watchdog mechanism to automatically recreate removed persistence artifacts. “The resulting implant operates as a fully featured Remote Access Trojan (RAT) capable of long-term persistence, espionage, lateral movement, and post-exploitation operations within compromised environments,” Securonix said.

The researchers assessed that the initial batch script is likely distributed via traditional phishing approaches. Meanwhile, the current scale and success rate of these attacks remain unknown.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Spain leads euro stablecoin usage on Brighty in 2025-2026

Spain accounts for 36% of EURC transactions and 25% of volume on the Brighty...

Banks Can Now Engage Crypto, But Risk Readiness Varies

Global regulators have established clear frameworks allowing banks to engage in crypto custody, execution,...

Australia payment rails may adapt for tokenized money

Australian regulators see tokenized money like stablecoins and deposit tokens as a design factor...

Linux “Copy Fail” Bug Lets Local Users Gain Root

A critical Linux flaw allows an unprivileged local user to write to a file's...

Strong Meta Q1 2026 Earnings Beat Can’t Prevent Stock Plunge

Meta's strong Q1 2026 earnings were overshadowed by a higher 2026 capex forecast, causing...

Must Read

Symbiosis Crypto Bridge: Your Guide to Moving Assets Between Blockchains

What is a Cross-Chain Crypto Bridge?Why Choose Symbiosis for Your Cross-Chain Needs?Support for 50+ BlockchainsAutomatic Routing for the Best RatesNo Need for RegistrationDirect Wallet...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading