New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials

Cybersecurity experts have revealed information on DEEP#DOOR, a stealthy Python-based backdoor architecture that can provide persistent access and gather a variety of sensitive data from compromised servers.

According to a report shared with The Hacker News by Securonix researchers Akshay Gaikwad, Shikha Sangwan, and Aaron Beardslee, “the intrusion chain starts with the execution of a batch script (‘install_obf.bat’) that disables Windows security controls, dynamically extracts an embedded Python payload (‘svc.py’), and establishes persistence through multiple mechanisms including Startup folder scripts, registry Run keys, scheduled tasks, and optional WMI subscriptions.”

It is determined that the batch script is disseminated by conventional methods such as phishing. The extent of attacks spreading the malware and if any of those infections have been effective are presently unknown read more about New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *