logo

Dindoor - The Technical Analysis of an Iranian Backdoor

ID: cee9ec89-0c5f-5bf5-ac1d-4080c5232cc1

STIX ID: report--cee9ec89-0c5f-5bf5-ac1d-4080c5232cc1

Feed Name: Binary Defense Blog

Threat Score
85/100

Date Published: 2026-08-25

Date Updated: 2026-08-26

...
...

Dindoor is a multi-stage backdoor linked to the Iranian APT MuddyWater that abuses the legitimate Deno JavaScript/TypeScript runtime to execute encoded payloads; it installs Deno if missing, uses base64-encoded stages, performs virtualization checks before establishing persistence via a Run registry key, and exposes a Deno-based TCP listener for C2. Binary Defense observed Dindoor targeting U.S. software and banking firms and a Canadian non-profit, and recommends behavior-based detections focused on the runtime and execution chain rather than static signatures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.