{"id":238192,"date":"2026-05-02T05:04:00","date_gmt":"2026-05-02T09:04:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/05\/02\/new-deepdoor-rat-uses-stealth-and-persistence-to-target-windows\/"},"modified":"2026-05-02T07:55:12","modified_gmt":"2026-05-02T11:55:12","slug":"new-deepdoor-rat-uses-stealth-and-persistence-to-target-windows","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/05\/02\/new-deepdoor-rat-uses-stealth-and-persistence-to-target-windows\/","title":{"rendered":"New Deep#Door RAT uses stealth and persistence to target Windows"},"content":{"rendered":"<p><a href=\"https:\/\/securityaffairs.com\/191567\/malware\/new-deepdoor-rat-uses-stealth-and-persistence-to-target-windows.html\">New Deep#Door RAT uses stealth and persistence to target Windows<\/a><\/p>\n<p><a href=\"https:\/\/securityaffairs.com\/191567\/malware\/new-deepdoor-rat-uses-stealth-and-persistence-to-target-windows.html\">https:\/\/securityaffairs.com\/191567\/malware\/new-deepdoor-rat-uses-stealth-and-persistence-to-target-windows.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-05-02 05:04:00<\/a><\/p>\n<p>Source Domain: <a href=\"securityaffairs.com\">securityaffairs.com<\/a><\/p>\n<p><h2>New Deep#Door RAT uses stealth and persistence to target Windows<\/h2>\n<\/p>\n<p>\t\t\t\t\t\t\t<span> Pierluigi Paganini<\/span><br \/>\n\t\t\t\t\t\t\t<span><img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/clock-icon.svg\" alt=\"\"\/> May 02, 2026<\/span><\/p>\n<p>\t\t\t\t\t\t<img decoding=\"async\" class=\"img-fluid mb-4\" src=\"https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/05\/image-4.png?fit=1600%2C951&#038;ssl=1\" alt=\"\"\/><\/p>\n<h2 class=\"wp-block-heading\">Deep#Door hides a Python RAT inside a batch file, kills Windows defenses, survives via multiple persistence methods, and exfiltrates data through a public TCP tunnel.<\/h2>\n<p>Security researchers at Securonix uncovered a sophisticated malware campaign called <strong>Deep#Door<\/strong>. Threat actors employed a stealthy Python-based backdoor that uses a surprisingly simple delivery method to achieve deep, persistent access on Windows systems. What makes the campaign stand out is not just what it can do, but how cleverly it avoids being caught doing it.<\/p>\n<p>\u201cUnlike traditional malware loaders that rely on external payload downloads, Deep#Door embeds its Python implant directly inside the dropper script and reconstructs it in-memory and on disk during execution.\u201d reads the <strong>report<\/strong> published by Securonix. \u201cThe implant then establishes communication with attacker infrastructure hosted on bore[.]pub, a publicly available TCP tunneling service, enabling stealthy remote access without exposing dedicated C2 servers.\u201d<\/p>\n<p>The attacK chain starts with a single batch file: install_obf.bat. When executed, this script reads itself, literally parsing its own contents to extract a hidden Python payload embedded directly inside the script. The extracted file, svc.py, is then written quietly to %LOCALAPPDATA%SystemServices, a folder name deliberately chosen to blend in with legitimate Windows components.<\/p>\n<p><img data-recalc-dims=\"1\" fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"609\" src=\"https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/05\/image-4.png?resize=1024%2C609&#038;ssl=1\" alt=\"\" class=\"wp-image-191577\" srcset=\"https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/05\/image-4.png?resize=1024%2C609&#038;ssl=1 1024w, https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/05\/image-4.png?resize=300%2C178&#038;ssl=1 300w, https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/05\/image-4.png?resize=768%2C456&#038;ssl=1 768w, https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/05\/image-4.png?resize=1536%2C913&#038;ssl=1 1536w, https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2026\/05\/image-4.png?w=1600&#038;ssl=1 1600w\" sizes=\"(max-width: 1000px) 100vw, 1000px\"\/><\/p>\n<p>This self-referential technique is a key reason the malware is hard to catch early. There are no suspicious downloads, no external URLs being contacted at the staging phase, and no compiled executables to flag. It\u2019s all happening within a script that looks, at first glance, like a routine maintenance tool.<\/p>\n<p>Before doing anything else, the loader systematically dismantles the host\u2019s defenses: Windows Defender is disabled,&#8230;<\/p>\n<p><a href=\"https:\/\/securityaffairs.com\/191567\/malware\/new-deepdoor-rat-uses-stealth-and-persistence-to-target-windows.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Deep#Door RAT uses stealth and persistence to target Windows https:\/\/securityaffairs.com\/191567\/malware\/new-deepdoor-rat-uses-stealth-and-persistence-to-target-windows.html Publish Date: 2026-05-02 05:04:00&#8230;<\/p>\n","protected":false},"author":1,"featured_media":238193,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/securityaffairs.com\/wp-content\/uploads\/2026\/05\/image-4.png","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[32],"class_list":["post-238192","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-malware"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/238192"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=238192"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/238192\/revisions"}],"predecessor-version":[{"id":238194,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/238192\/revisions\/238194"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/238193"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=238192"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=238192"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=238192"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}