logo

MuddyWater-Linked Dindoor Backdoor Abuses Legitimate Deno Runtime to Evade Detection

ID: ec6eb3d5-0230-5e3a-b30e-dcf5a6e3cb7a

STIX ID: report--ec6eb3d5-0230-5e3a-b30e-dcf5a6e3cb7a

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

Author: Varshini

...
...

Researchers attribute a backdoor called Dindoor to the MuddyWater APT; the malware abuses the legitimate Deno JavaScript/TypeScript runtime (downloading deno.land if needed) to run Base64-encoded scripts, performs multi-stage payload retrieval and sandbox/VM detection via a WMI video controller query, establishes persistence via a Run key executing a VBScript (Lynx_system59.vbs), and uses signed tools (curl.exe, deno.exe, wscript.exe, PowerShell) for C2 and concealment — infections were observed at U.S. software and banking organizations and a Canadian non-profit.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.