Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Python Backdoor Threat Analysis Following an AI Deepfake Impersonation Campaign

choisy.fr

TLP:CLEAR
Active

Domain

Description

A sophisticated campaign linked to APT37 delivers Python-based backdoors through spear-phishing emails containing malicious LNK files disguised as legitimate documents. Attackers use themes including airline e-tickets, North Korea research invitations, and impersonation of defense and police officials to induce execution. The LNK files employ environment variable-based obfuscation techniques to download additional BAT files, which establish a Python runtime environment and execute compiled Python bytecode disguised with .cat extensions. The malware functions as a remote command execution backdoor, communicating with C2 servers to receive commands and exfiltrate results. Persistence is maintained through scheduled tasks executing at one-minute intervals. The campaign shows strong tactical similarities to previous APT37 operations, including infrastructure patterns, script obfuscation methods, and the abuse of legitimate tools.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Python Backdoor Threat Analysis Following an AI Deepfake Impersonation Campaign
Pattern Type
STIX
Confidence
75%
Valid From
May 14, 2026 23:08
Total Sightings
0
Added
May 14, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of choisy.fr

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.