DinDoor Backdoor Abuses Deno and MSI Installers To Evade Security Tools
ID: dbb3143e-57e4-547e-9753-29ffc69ba3f7
STIX ID: report--dbb3143e-57e4-547e-9753-29ffc69ba3f7
Feed Name: Cyber Press
## Executive Summary Researchers analyzed DinDoor, a DinDoor malware campaign that weaponizes the legitimate Deno JavaScript runtime and deceptive MSI installers to execute obfuscated scripts and evade traditional defenses. Samples include a dropped PowerShell script and a fileless variant that installs Deno and uses a hardcoded JWT to reveal a shared C2 backend (serialmenot.com); investigators mapped ~20 active malicious servers by hunting for distinctive Caddy proxy headers and specific 404 behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
