WhirlCoil Python loader remote tunnel backdoor
Malware Activity
Summary
Hide ▲
Show ▼
The WhirlCoil Python loader now has confirmed Visual Studio Code remote tunnel persistence, giving operators backdoor access and the ability to execute arbitrary commands on compromised hosts. It also harvests system information and user-directory contents, increasing exposure on targeted systems. The activity matters because the tunnel provides durable remote control through a legitimate developer feature rather than a one-off payload run.
Related Happenings
MIMICRAT (aka AstarionRAT) ClickFix-delivered RAT activity
Malware Activity
H score22
First: 20.02.2026 13:55
Last: 20.02.2026 13:55
Sources 1
About this happening:
The MIMICRAT (aka AstarionRAT) malware has been disclosed as a ClickFix-delivered RAT that enables Windows token impersonation and SOCKS5 tunneling, increasing the...
MIMICRAT (aka AstarionRAT) ClickFix-delivered RAT activity
Malware ActivityAbout this happening: The MIMICRAT (aka AstarionRAT) malware has been disclosed as a ClickFix-delivered RAT that enables Windows token impersonation and SOCKS5 tunneling, increasing the...
React/Next.js applications React2Shell RCE flaw (CVE-2025-55182)
Vulnerability
H score54
First: 09.02.2026 10:37
Last: 09.02.2026 10:37
Sources 1
About this happening:
React2Shell (CVE-2025-55182) has been repeatedly exploited against React Server Components (RSC) and Next.js systems, with Huntress saying the first attempt it saw cam...
React/Next.js applications React2Shell RCE flaw (CVE-2025-55182)
VulnerabilityAbout this happening: React2Shell (CVE-2025-55182) has been repeatedly exploited against React Server Components (RSC) and Next.js systems, with Huntress saying the first attempt it saw cam...
Latest development: 09.03.2026 23:45
Google reports that newly disclosed third-party flaws are increasingly being exploited for initial access to cloud environments, with React2Shell (CVE-2025-55182) and CVE-2025-24893 highlighted as frequent RCE examples. The report says attackers are weaponizing new flaws within days, with cryptominers observed within 48 hours of vulnerability disclosure.
AsyncRAT distribution via TryCloudflare, Dropbox, and WSH infection chain
Malware Activity
H score27
First: 14.01.2026 16:18
Last: 14.01.2026 16:18
Sources 1
About this happening:
A multi-stage phishing chain is distributing AsyncRAT through TryCloudflare tunnels and Dropbox ZIP links, creating a persistent Windows infection path that en...
AsyncRAT distribution via TryCloudflare, Dropbox, and WSH infection chain
Malware ActivityAbout this happening: A multi-stage phishing chain is distributing AsyncRAT through TryCloudflare tunnels and Dropbox ZIP links, creating a persistent Windows infection path that en...
TA415 phishing campaign targeting US policy entities
Campaign
H score36
First: 17.09.2025 15:59
Last: 17.09.2025 15:59
Sources 1
About this happening:
The TA415 phishing campaign targeted US government, think tank, and academic organizations in July and August 2025, raising the risk of persistent remote access to...
TA415 phishing campaign targeting US policy entities
CampaignAbout this happening: The TA415 phishing campaign targeted US government, think tank, and academic organizations in July and August 2025, raising the risk of persistent remote access to...
Warlock ransomware SharePoint credential-dumping and deployment activity
Malware Activity
H score38
First: 21.08.2025 00:04
Last: 21.08.2025 00:04
Sources 1
About this happening:
The Warlock ransomware operation is compromising exposed on-premises SharePoint servers, creating risk of credential theft, lateral movement, and disruptive rans...
Warlock ransomware SharePoint credential-dumping and deployment activity
Malware ActivityAbout this happening: The Warlock ransomware operation is compromising exposed on-premises SharePoint servers, creating risk of credential theft, lateral movement, and disruptive rans...
Timeline
-
17.09.2025 15:56 2 articles · 10mo ago
Initial report: WhirlCoil Python loader remote tunnel backdoor
Initial DisclosureInitial execution begins when a hidden batch script launches the WhirlCoil Python loader from a password-protected archive. A decoy PDF is shown to the user while the loader prepares persistence on the host.
Show sources
- Chinese TA415 Uses VS Code Remote Tunnels to Spy on U.S. Economic Policy Experts — thehackernews.com — 17.09.2025 15:56
- Chinese TA415 Uses VS Code Remote Tunnels to Spy on U.S. Economic Policy Experts — thehackernews.com — 17.09.2025 15:56