Fake software on GitHub and SourceForge distribute Deno RAT
ID: f2410b2f-78a5-5007-ac6f-8e132c12c792
STIX ID: report--f2410b2f-78a5-5007-ac6f-8e132c12c792
Feed Name: Malwarebytes Blog
This report details an active campaign where attackers host fake installers and plugins on GitHub and SourceForge (promoted via compromised YouTube channels) to install Deno and deploy the DinDoor backdoor and a Deno-based RAT capable of full remote control, credential and crypto-wallet theft, and peer-to-peer screen streaming via a hidden Edge instance; the analysis includes infection chains, persistence mechanisms, network C2 endpoints, capabilities, and a list of URLs, domains, and IP IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
