HomeSecurityNew Python Backdoor uses Tunneling to steal credentials

New Python Backdoor Uses Tunneling to Steal Credentials

Cybersecurity researchers have revealed details of a silent Python-based backdoor, dubbed DEEP#DOOR, which has the capabilities to establish permanent access and collect a wide range of sensitive information from compromised systems.

See also: WordPress: Backdoor detected in Quick Page/Post Redirect plugin

Python

The attack chain begins by executing a batch script ('install_obf.bat') that disables Windows security checks, dynamically extracts an embedded Python payload ('svc.py'), and establishes persistent access via multiple mechanisms, including Startup folder scripts , Run registry keys , scheduled tasks, and optional WMI subscriptions .

It is estimated that the batch script is distributed via traditional methods such as phishing. At present, it is not known how widespread the attacks distributing the malware are, nor whether any of these infections have been successful.

What makes the attack chain remarkable is that the underlying Python implant is embedded directly within the dropper script, from where it is extracted, reconstructed, and executed. This reduces the need for repeated communication with external infrastructure and minimizes the footprint for forensic analysis.

Once launched, the malware establishes communication with “bore[.]pub,” a Rust-based tunneling service, allowing the operator to issue commands that facilitate remote command execution and extensive monitoring. This includes system identification, clipboard monitoring, ambient audio recording, collection of web browser credentials, credentials stored in Google Chrome, Mozilla Firefox, and Windows Credential Manager, and theft of cloud credentials (Amazon Web Services, Google Cloud, and Microsoft Azure).

See also: FIRESTARTER backdoor targeted federal Cisco Firepower device

New Python Backdoor Uses Tunneling to Steal Credentials

Using a public TCP tunneling service for command and control (C2) offers several advantages, as it eliminates the need to install special infrastructure, mixes malicious traffic, and avoids embedding server details into the payload.

At the same time, DEEP#DOOR incorporates a series of defense analysis and evasion mechanisms, such as sandbox, debugger and virtual machine (VM) detection, AMSI and Event Tracing for Windows (ETW) patching, NTDLL unhooking, Microsoft Defender spoofing, SmartScreen bypass, PowerShell logging suppression, command line deletion, timestamp modification and log file scrubbing, to remain unnoticed and hinder incident response efforts.

Furthermore, it uses multiple persistent access mechanisms that include creating scripts in the Windows Startup folder, Run keys in the registry, and scheduled tasks, while it also relies on a monitoring mechanism to ensure that persistent access objects have not been removed, and if so, it automatically recreates them, making recovery difficult.

The resulting implant operates as a fully-featured Remote Access Trojan (RAT) capable of long-term persistent access, espionage, lateral movement, and post-exploit operations within compromised environments. The implant prioritizes detection avoidance and forensic visibility by directly tampering with Windows security and telemetry mechanisms.

See also: Trivy Attack: Malware on Docker Hub and Kubernetes Wiper

New Python Backdoor Uses Tunneling to Steal Credentials

DEEP#DOOR highlights the continued evolution of malicious actors towards fileless, script-based intrusion frameworks that rely heavily on native system components and interpreted languages ​​such as Python. By embedding the payload directly into the dropper and extracting it at runtime, the malware significantly reduces external dependencies and limits traditional detection opportunities.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS