logo

DinDoor Backdoor Abuses Deno and MSI Installers To Evade Security Tools

ID: dbb3143e-57e4-547e-9753-29ffc69ba3f7

STIX ID: report--dbb3143e-57e4-547e-9753-29ffc69ba3f7

Feed Name: Cyber Press

Threat Score
82/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

Author: Varshini

...
...

## Executive Summary Researchers analyzed DinDoor, a DinDoor malware campaign that weaponizes the legitimate Deno JavaScript runtime and deceptive MSI installers to execute obfuscated scripts and evade traditional defenses. Samples include a dropped PowerShell script and a fileless variant that installs Deno and uses a hardcoded JWT to reveal a shared C2 backend (serialmenot.com); investigators mapped ~20 active malicious servers by hunting for distinctive Caddy proxy headers and specific 404 behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.