BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

DEEP#DOOR Python Backdoor Steals Cloud Credentials

Sophisticated Python backdoor DEEP#DOOR steals cloud credentials via tunneling.

  • A stealthy Python backdoor called DEEP#DOOR uses a tunneling service for command-and-control to steal sensitive data, including cloud credentials and SSH keys.
  • The malware embeds its payload directly within the dropper script to minimize forensic traces and employs multiple anti-analysis mechanisms to evade detection.
  • Securonix researchers detail how the framework establishes persistent access through various system mechanisms, making remediation difficult.

Cybersecurity researchers from Securonix have disclosed details of a sophisticated Python-based backdoor framework called DEEP#DOOR, which was designed to harvest extensive data from compromised systems, according to a report shared with The Hacker News in late April 2026.

- Advertisement -

The attack chain begins with a batch script that disables Windows security controls and dynamically extracts an embedded Python payload. Consequently, it establishes persistence through Startup folder scripts, registry Run keys, and scheduled tasks.

This approach reduces the need for external infrastructure, thereby minimizing the forensic footprint. The malware then establishes communication with a public Rust-based tunneling service called “bore[.]pub.”

The operator can then issue commands for reverse shell access and extensive surveillance. These capabilities include keylogging, clipboard monitoring, webcam access, and ambient audio recording.

The framework also harvests credentials from web browsers, Windows Credential Manager, and major cloud platforms like AWS, Google Cloud, and Microsoft Azure. It additionally extracts SSH keys for further network compromise.

- Advertisement -

Using a public tunneling service for command-and-control blends malicious traffic with legitimate network activity. This tactic avoids embedding server details within the payload itself.

DEEP#DOOR incorporates numerous anti-analysis and defense evasion mechanisms to complicate incident response. These include sandbox detection, ETW patching, Microsoft Defender tampering, and log clearing.

It also employs a watchdog mechanism to automatically recreate removed persistence artifacts. “The resulting implant operates as a fully featured Remote Access Trojan (RAT) capable of long-term persistence, espionage, lateral movement, and post-exploitation operations within compromised environments,” Securonix said.

The researchers assessed that the initial batch script is likely distributed via traditional phishing approaches. Meanwhile, the current scale and success rate of these attacks remain unknown.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Ethereum Nears $2,000 As Market-Wide Correction Deepens

Ethereum (ETH) is facing a steep correction, falling 2.9% in the last 24 hours...

Bitcoin Depot Files Bankruptcy, Shuts Down ATM Network

Bitcoin Depot, North America's largest Bitcoin ATM operator, has filed for Chapter 11 bankruptcy...

Oil Inflation Fears Cloud Ethereum’s Tokenization Story

Fundstrat's Tom Lee identifies surging oil prices, with WTI crude above $106, as Ethereum's...

Kraken AI layoffs push US IPO to 2027

Cryptocurrency exchange Kraken has reportedly laid off approximately 150 employees, attributing the move to...

Crypto Market Plunges, $660M Liquidated in 24 Hours

Bitcoin has plunged to near $76,000, triggering over $660 million in market liquidations.Higher inflation,...

Must Read

How To Buy a Handshake Domain: A Step-by-Step Guide

Handshake Domains | Benefits | Drawbacks | How To Buy | Supported BrowsersIn this step-by-step guide, I am going to show you how to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading