
Malicious Tortoise SVN Version Bundled with Backdoor Detected
The video examines a malicious version of Tortoise SVN, a legitimate software tool, which appears to be bundled with a backdoor. The analysis compares the malware-laden version (left) with the genuine software (right), highlighting suspicious timestamps—most files are dated 2024, while one file is dated 2025, suggesting tampering. The malicious sample employs DLL side-loading and initiates network connections from Tortoise Blame to an unusual domain, main.webkratos.ddns.doguru.com, which is not typical behavior for the legitimate tool. The domain is suspected to function as a command-and-control (C2) server, potentially using a web socket for communication. The presenter questions whether this behavior is normal for Tortoise SVN, implying it is likely part of the backdoor’s operation. No specific threat actor or distribution method is identified in the transcript.