Abuse of alternative runtime environments Deno-tes defender headaches
ID: 278003d6-d961-5627-9c01-6b28a820a753
STIX ID: report--278003d6-d961-5627-9c01-6b28a820a753
Feed Name: Sophos Blogs
This Sophos MDR report examines a set of intrusions in early 2026 where threat actors used MSI installers, VBS and PowerShell loaders, and living-off-the-land binaries to deploy the Deno runtime and execute obfuscated JavaScript payloads in-memory for host fingerprinting, persistent C2, and staged payload retrieval; the report contains a detailed MSI sample analysis, persistence and execution chains, observed IoCs and JWT-based campaign tracking, and recommended detection/mitigation opportunities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
