logo

Iran-Linked Threat Actors Deploy Dindoor Backdoor via Deno Runtime

ID: 46805e0c-0493-5b30-b2de-8385981c89de

STIX ID: report--46805e0c-0493-5b30-b2de-8385981c89de

Feed Name: ThreatCluster

Threat Score
70/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

...
...

Iran-linked MuddyWater actors are deploying a Windows backdoor called Dindoor that leverages the legitimate Deno runtime to run malicious JavaScript/TypeScript payloads, complicating detection; Dindoor has been observed as a later-stage payload in spearphishing campaigns targeting U.S. software companies, and organizations using Deno are advised to enhance monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.