Briefing

New Python Backdoor Framework DEEP#DOOR Enables Persistent Access and Data Theft

security
by [email protected] (The Hacker News) ·

Detect and block DEEP#DOOR by monitoring for its batch script and disabling Windows security controls.

What to do now

Implement endpoint detection to block DEEP#DOOR execution.

Summary

A new stealthy backdoor framework named DEEP#DOOR has been disclosed by cybersecurity researchers, offering attackers persistent access and the ability to harvest a wide range of sensitive information from compromised Windows hosts. The intrusion chain begins with the execution of a batch script called install_obf.bat, which disables Windows security controls and dynamically extracts credentials from the system. DEEP#DOOR then installs a lightweight agent that can exfiltrate data, manipulate system settings, and maintain persistence across reboots. The framework is written in Python and includes modules for credential dumping, keylogging, and remote command execution. Researchers noted that the backdoor can evade standard endpoint detection by using obfuscated code and legitimate system utilities. The attackers can also use the framework to pivot to other machines within the same network. The discovery underscores the need for robust endpoint protection and continuous monitoring.

Key changes

  • DEEP#DOOR is a stealthy Python backdoor framework for persistent access.
  • Intrusion chain starts with batch script install_obf.bat disabling Windows security.
  • Framework installs lightweight agent for data exfiltration and persistence.
  • Includes modules for credential dumping, keylogging, remote command execution.
  • Evades endpoint detection using obfuscated code and legitimate utilities.
  • Enables pivoting to other machines within the same network.

Affects

internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting