Iran-Linked Hackers Abuse Legitimate Deno Runtime to Hide Dindoor Backdoor on Windows Systems
ID: 426825bc-89b7-5f86-b9bc-dc25489848f7
STIX ID: report--426825bc-89b7-5f86-b9bc-dc25489848f7
Feed Name: GBHackers
Threat Score
Iran-linked MuddyWater operators deployed a Windows backdoor called Dindoor that hijacks the legitimate Deno runtime (downloaded via curl.exe) to execute Base64-encoded JavaScript/TypeScript payloads; the campaign uses signed/common binaries, layered obfuscation, virtualization checks to evade sandboxes, and script-based persistence (wscript.exe VBScript in AppData with a Run key) to maintain stealth and communicate with C2 over obfuscated TCP.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
