logo

New DinDoor Backdoor Abuses Deno Runtime and MSI Installers to Evade Detection

ID: dba8599a-8e8a-5367-8f17-e355ede23ac0

STIX ID: report--dba8599a-8e8a-5367-8f17-e355ede23ac0

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

Author: Tushar Subhra Dutta

...
...

DinDoor is a newly identified backdoor that leverages signed MSI installers and the legitimate Deno JavaScript runtime to evade detection: delivered via phishing or malicious drive-by MSIs, it installs or invokes deno.exe to run obfuscated JavaScript (sometimes entirely in-memory), fingerprints hosts, binds a localhost TCP mutex, and communicates with C2 servers (researchers found 20 active servers across 15 ASNs). Analysts link DinDoor to a Tsundere Botnet variant and possibly the Iranian APT Seedworm/MuddyWater; notable IOCs and detection cues include deno.exe running as a child of powershell.exe or wscript.exe, command lines like "deno.exe -A data:application/javascript;base64", TCP binds on localhost ports 10044/10091, Via:1.1 Caddy headers, and the domain serialmenot.com. Recommended mitigations include restricting MSI execution via AppLocker or Windows Defender Application Control, monitoring for the deno.exe command-line and local TCP binds, reviewing HTTP logs for the noted headers, and blocking associated domains and hosting providers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.