logo

Hackers Use Fake ChatGPT and Claude Installers to Deploy DinDoor Backdoor

ID: f5c63c0a-72af-55d8-8c93-95635152f8f7

STIX ID: report--f5c63c0a-72af-55d8-8c93-95635152f8f7

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-27

Date Updated: 2026-05-28

Author: Tushar Subhra Dutta

...
...

A widespread campaign is distributing the DinDoor backdoor and a Deno-based RAT by hosting convincing fake installers and plugins on trusted platforms (GitHub, SourceForge) and driving traffic with compromised YouTube channels; the malware steals browser and crypto wallet data, establishes persistent access, enables remote control and hidden screen streaming via a hijacked Edge process, and uses techniques (Scoop/WinGet, Cloudflare Workers) to evade detection. Multiple IoCs (malicious repositories, domains, and IPs) are provided to support detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.