logo

Iran-Linked Hackers Abuse Legitimate Deno Runtime to Hide Dindoor Backdoor on Windows Systems

ID: 426825bc-89b7-5f86-b9bc-dc25489848f7

STIX ID: report--426825bc-89b7-5f86-b9bc-dc25489848f7

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

Author: Mayura Kathir

...
...

Iran-linked MuddyWater operators deployed a Windows backdoor called Dindoor that hijacks the legitimate Deno runtime (downloaded via curl.exe) to execute Base64-encoded JavaScript/TypeScript payloads; the campaign uses signed/common binaries, layered obfuscation, virtualization checks to evade sandboxes, and script-based persistence (wscript.exe VBScript in AppData with a Run key) to maintain stealth and communicate with C2 over obfuscated TCP.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.