MuddyWater-Linked Dindoor Backdoor Abuses Legitimate Deno Runtime to Evade Detection
ID: ec6eb3d5-0230-5e3a-b30e-dcf5a6e3cb7a
STIX ID: report--ec6eb3d5-0230-5e3a-b30e-dcf5a6e3cb7a
Feed Name: Cyber Press
Researchers attribute a backdoor called Dindoor to the MuddyWater APT; the malware abuses the legitimate Deno JavaScript/TypeScript runtime (downloading deno.land if needed) to run Base64-encoded scripts, performs multi-stage payload retrieval and sandbox/VM detection via a WMI video controller query, establishes persistence via a Run key executing a VBScript (Lynx_system59.vbs), and uses signed tools (curl.exe, deno.exe, wscript.exe, PowerShell) for C2 and concealment — infections were observed at U.S. software and banking organizations and a Canadian non-profit.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
