logo

DinDoor Backdoor: Deno Runtime Abuse and 20 Active C2 Servers

ID: 832df3bb-0f85-54b7-a54c-3a936200c6d8

STIX ID: report--832df3bb-0f85-54b7-a54c-3a936200c6d8

Feed Name: Hunt.io Blog

Threat Score
75/100

Date Published: 2026-04-22

Date Updated: 2026-04-28

...
...

This report analyzes DinDoor, a Deno-based backdoor delivered via malicious MSI installers, comparing two samples that use differing execution methods (one writes JS to disk, the other executes JS in-memory). It documents the payload's host fingerprinting, C2 interaction (including a hardcoded JWT linking to serialmenot.com), network indicators and 20 active servers discovered via a HuntSQL query, and provides mitigation steps and IOCs for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.