Malware · 137 days ago
Windows endpoints can be turned into long-lived espionage nodes when the implant is built to disable defenses, hide in normal startup paths, and reconstruct itself in memory. The standard response of finding and deleting a file misses the point here. The backdoor is designed to survive, blend in, and leave less forensic evidence behind.
Securonix says Deep#Door is a Python-based Windows backdoor delivered through batch scripts that disable SmartScreen, firewall logging, Defender tamper protection, and AMSI. It then sets multi-layered persistence through Run keys, scheduled tasks, and Startup folder entries, and supports command execution, reconnaissance, keylogging, clipboard capture, screenshotting, microphone and webcam access, and credential and SSH key theft.
The same implant can also pivot into disruption by overwriting the Master Boot Record, crashing systems, or exhausting resources with process spawning. That mix of espionage and sabotage means recovery can take longer than a normal malware cleanup, because the payload is built to fragment evidence and keep access alive.
3 sources covering this story
Sophisticated Deep#Door Backdoor Enables Espionage, Disruption
The stealthy Python-based backdoor framework deploys a persistent Windows implant likely designed for espionage.
New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials
DEEP#DOOR embeds a Python RAT in a dropper script, using bore[.]pub C2 to steal credentials and evade Windows defenses, complicating detection.
Deep#Door Python Backdoor Evades Detection On Windows
Deep#Door Python RAT uses tunneling and obfuscation to evade detection and steal credentials
Part of the PlainSec briefing for 2026-05-02