#WindowsThreat
Deep#Door is a stealthy Python-based backdoor targeting Windows, enabling persistent remote command execution and deep surveillance by disabling security controls and using layered persistence with advanced evasion tactics. #DeepDoor #WindowsThreat
Sophisticated Deep#Door Backdoor Enables Espionage, Disruption
Securonix has identified Deep#Door, a stealthy Python-based backdoor that gives attackers persistent remote command execution and extensive surveillance on Windows systems. The threat uses embedded Python in batch scripts, disables security controls, establishes multi-layered persistence, and employs advanced in-memory and evasion techniques to remain covert and resilient. #DeepDoor #Windows...
www.hendryadrian.com
May 1, 2026 at 1:30 PM
A WhatsApp malware campaign uses VBS scripts to deploy additional payloads and MSI backdoors via cloud storage, exploiting renamed system utilities and UAC bypass to evade detection and escalate privileges. #VBSattack #WindowsThreat #Microsoft
WhatsApp malware campaign delivers VBS payloads and MSI backdoors
Microsoft Defender Security Research details a campaign in which malicious VBS scripts delivered via WhatsApp download additional VBS payloads and MSI installers from cloud storage, leveraging renamed system utilities and UAC bypass attempts to evade detection and escalate privileges. The report provides Microsoft Defender detections, hunting queries, mitigation recommendations (EDR in block mode, network and web protection, tamper protection, attack surface reduction rules), and IOCs including SHA-256 hashes, cloud storage URLs, and C2 domains. #TrojanVBS_ObfuseKPP #Neescil_top
www.hendryadrian.com
March 31, 2026 at 10:40 PM
DeepLoad malware uses the ClickFix lure to trick users into running PowerShell via mshta.exe, employing AI obfuscation, in-memory injection, and WMI persistence to steal browser credentials and evade detection. #DeepLoad #WindowsThreat
DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials
Researchers found a new campaign that uses the ClickFix social engineering lure to run an undocumented loader called DeepLoad, which leverages AI-assisted obfuscation, in-memory APC injection, and immediate credential theft to evade static detection. DeepLoad hides inside legitimate Windows processes (e.g., LockAppHost.exe), compiles randomized temporary DLLs via Add-Type, uses WMI for...
www.hendryadrian.com
March 30, 2026 at 11:00 PM