Stealthy Python RAT Uses Hidden C2 Tunnel to Harvest Browser and Cloud Credentials

1 min read
Source: The Hacker News
Stealthy Python RAT Uses Hidden C2 Tunnel to Harvest Browser and Cloud Credentials
Photo: The Hacker News
TL;DR Summary

Security researchers uncovered DEEP#DOOR, a Python-based backdoor that embeds its payload in a dropper and gains persistence via Startup scripts, Run keys, Scheduled Tasks, and optional WMI subscriptions. It uses a Rust-based tunneling service (bore.pub) for C2 and offers full RAT capabilities—reverse shell, reconnaissance, keylogging, screen/audio capture, webcam access, and credential theft from browsers, cloud services, and Windows Credential Manager—while employing anti-analysis and defense-evasion techniques. Distribution appears phishing-based and targeted, with a modular, fileless design; it could be repurposed by different actors.

Share this article

Reading Insights

Total Reads

0

Unique Readers

17

Time Saved

3 min

vs 3 min read

Condensed

86%

58682 words

Want the full story? Read the original article

Read on The Hacker News