New DinDoor Backdoor Abuses Deno Runtime and MSI Installers to Evade Detection
ID: dba8599a-8e8a-5367-8f17-e355ede23ac0
STIX ID: report--dba8599a-8e8a-5367-8f17-e355ede23ac0
Feed Name: cybersecurityNews.com
DinDoor is a newly identified backdoor that leverages signed MSI installers and the legitimate Deno JavaScript runtime to evade detection: delivered via phishing or malicious drive-by MSIs, it installs or invokes deno.exe to run obfuscated JavaScript (sometimes entirely in-memory), fingerprints hosts, binds a localhost TCP mutex, and communicates with C2 servers (researchers found 20 active servers across 15 ASNs). Analysts link DinDoor to a Tsundere Botnet variant and possibly the Iranian APT Seedworm/MuddyWater; notable IOCs and detection cues include deno.exe running as a child of powershell.exe or wscript.exe, command lines like "deno.exe -A data:application/javascript;base64", TCP binds on localhost ports 10044/10091, Via:1.1 Caddy headers, and the domain serialmenot.com. Recommended mitigations include restricting MSI execution via AppLocker or Windows Defender Application Control, monitoring for the deno.exe command-line and local TCP binds, reviewing HTTP logs for the noted headers, and blocking associated domains and hosting providers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
