Find notable cyber news and cases, enriched with sources, timelines, and signals.

WhirlCoil Python loader remote tunnel backdoor

Malware Activity
First reported
Last updated
Happening score
H score 22
1 unique sources, 1 articles

Summary

Hide ▲

The WhirlCoil Python loader now has confirmed Visual Studio Code remote tunnel persistence, giving operators backdoor access and the ability to execute arbitrary commands on compromised hosts. It also harvests system information and user-directory contents, increasing exposure on targeted systems. The activity matters because the tunnel provides durable remote control through a legitimate developer feature rather than a one-off payload run.

Related Happenings

MIMICRAT (aka AstarionRAT) ClickFix-delivered RAT activity

Malware Activity
H score22 First: 20.02.2026 13:55 Last: 20.02.2026 13:55 Sources 1

About this happening: The MIMICRAT (aka AstarionRAT) malware has been disclosed as a ClickFix-delivered RAT that enables Windows token impersonation and SOCKS5 tunneling, increasing the...

React/Next.js applications React2Shell RCE flaw (CVE-2025-55182)

Vulnerability
H score54 First: 09.02.2026 10:37 Last: 09.02.2026 10:37 Sources 1

About this happening: React2Shell (CVE-2025-55182) has been repeatedly exploited against React Server Components (RSC) and Next.js systems, with Huntress saying the first attempt it saw cam...

Latest development: 09.03.2026 23:45

Google reports that newly disclosed third-party flaws are increasingly being exploited for initial access to cloud environments, with React2Shell (CVE-2025-55182) and CVE-2025-24893 highlighted as frequent RCE examples. The report says attackers are weaponizing new flaws within days, with cryptominers observed within 48 hours of vulnerability disclosure.

AsyncRAT distribution via TryCloudflare, Dropbox, and WSH infection chain

Malware Activity
H score27 First: 14.01.2026 16:18 Last: 14.01.2026 16:18 Sources 1

About this happening: A multi-stage phishing chain is distributing AsyncRAT through TryCloudflare tunnels and Dropbox ZIP links, creating a persistent Windows infection path that en...

TA415 phishing campaign targeting US policy entities

Campaign
H score36 First: 17.09.2025 15:59 Last: 17.09.2025 15:59 Sources 1

About this happening: The TA415 phishing campaign targeted US government, think tank, and academic organizations in July and August 2025, raising the risk of persistent remote access to...

Warlock ransomware SharePoint credential-dumping and deployment activity

Malware Activity
H score38 First: 21.08.2025 00:04 Last: 21.08.2025 00:04 Sources 1

About this happening: The Warlock ransomware operation is compromising exposed on-premises SharePoint servers, creating risk of credential theft, lateral movement, and disruptive rans...

Timeline

  1. 17.09.2025 15:56 2 articles · 10mo ago

    Initial report: WhirlCoil Python loader remote tunnel backdoor

    Initial Disclosure

    Initial execution begins when a hidden batch script launches the WhirlCoil Python loader from a password-protected archive. A decoy PDF is shown to the user while the loader prepares persistence on the host.

    Show sources