Threats Feed|MuddyWater|Last Updated 28/04/2026|AuthorCertfa Radar|Publish Date21/04/2026

DinDoor Malware Exploits Deno Runtime to Target US and Russian Entities

  • Actor Motivations: Espionage,Exfiltration,Extortion,Financial Gain
  • Attack Vectors: Backdoor,Botnet,Downloader,Fileless malware,Ransomware,Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/High Probability

Threat Overview

DinDoor, a modular Tsundere botnet variant linked to state-sponsored actors like MuddyWater and cybercrime clusters, exploits the Deno runtime to execute obfuscated JavaScript, effectively bypassing traditional endpoint detections. Delivered via deceptive MSI files, recent campaigns have targeted U.S. organizations and the Russian financial services sector. Upon execution, the malware binds a local port as a mutex, aggressively fingerprints the victim’s hardware, and communicates with a multi-tenant command and control (C2) infrastructure, notably serialmenot[.]com. By analyzing unique Caddy proxy HTTP response headers, researchers identified 20 active C2 servers. Ultimately, DinDoor demonstrates how threat actors increasingly abuse trusted, signed runtimes and shared backend platforms to conceal their operations.

Detected Targets

TypeDescriptionConfidence
CaseMigCredit
MigCredit is a prominent microfinance organization (MFO) that operates primarily in Russia. MigCredit has been targeted by MuddyWater as the main target.
Verified
SectorFinancial
Verified
RegionRussia
Verified
RegionUnited States
Verified

Extracted IOCs

  • aeeracaspsl[.]site
  • annaionovna[.]com
  • bitatits[.]surf
  • hngfbgfbfb[.]cyou
  • ilspaeysoff[.]site
  • ineracaspsl[.]site
  • justtalken[.]com
  • landmas[.]info
  • myspaeysoff[.]site
  • playerdragonbike[.]com
  • weaplink[.]com
  • bandage.healthydefinitetrunk[.]com
  • generalnewlong.comagilemast3r.duckdns[.]org
  • grafana.healthydefinitetrunk[.]com
  • surgery.healthydefinitetrunk[.]com
  • 2a09bbb3d1ddb729ea7591f197b5955453aa3769c6fb98a5ef60c6e4b7df23a5
  • 7b793c54a927da36649eb62b9481d5bcf1e9220035d95bbfb85f44a6cc9541ae
  • 138[.]124.240.76
  • 138[.]124.240.77
  • 140[.]82.18.48
  • 146[.]19.254.84
  • 178[.]104.137.180
  • 178[.]16.52.191
  • 185[.]218.19.117
  • 192[.]109.200.151
  • 193[.]233.82.43
  • 193[.]24.123.25
  • 194[.]48.141.192
  • 199[.]217.99.189
  • 199[.]91.220.142
  • 199[.]91.220.216
  • 209[.]99.189.170
  • 2[.]26.117.169
  • 2[.]27.122.16
  • 45[.]135.180.200
  • 45[.]151.106.88
  • 85[.]192.27.152
download

Tip: 37 related IOCs (20 IP, 15 domain, 0 URL, 0 email, 2 file hash) to this threat have been found.

Overlaps

Void ManticoreIranian MOIS Actors Weaponize Cybercrime Ecosystems for State Operations

Source: Check Point - March 2026

Detection (one case): 2a09bbb3d1ddb729ea7591f197b5955453aa3769c6fb98a5ef60c6e4b7df23a5

SeedwormIranian APT Seedworm Targets U.S., Israel, and Canada with Novel Backdoors

Source: Symantec - March 2026

Detection (one case): 2a09bbb3d1ddb729ea7591f197b5955453aa3769c6fb98a5ef60c6e4b7df23a5

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Understanding the DinDoor Malware Threat

Cybersecurity researchers discovered a malware family named DinDoor that is compromising computers by hijacking a legitimate developer application called Deno. By analyzing the unique way the attackers configured their web servers, investigators were able to expose 20 active control servers managing the malware across the internet.

The infrastructure running DinDoor is shared among multiple threat actors operating on a "Malware-as-a-Service" model. Evidence links this shared platform to state-sponsored groups like the Iranian-aligned Seedworm (also known as MuddyWater), as well as financially motivated cybercrime groups.

The primary goal is to establish a hidden, persistent backdoor on a victim's system. Once installed, the malware generates a unique fingerprint of the computer, checks to ensure it isn't running in a security researcher's test environment, and quietly waits for further malicious commands or payloads from the attackers.

Targeting depends heavily on which specific threat group is using the shared platform at a given time. For instance, one discovered attack was disguised as a document from a Russian microloan company, indicating targeted financial espionage, while other campaigns using this malware have historically focused on U.S. organizations.

Attackers trick users into opening deceptive installation files, sometimes disguised as simple PDF documents. When opened, these files might show a fake error message to confuse the user, while secretly downloading a runtime tool and executing hidden malicious scripts directly into the computer's memory.

Because the platform is used by both state-sponsored spies and cybercriminals, victims are attractive for different reasons. Government-backed actors use it to steal sensitive organizational data and intellectual property, while cybercriminals use it to establish a foothold for financial extortion or ransomware deployment.

It is a targeted threat utilizing a widespread, shared infrastructure. Various hacking groups rent or share the underlying technology to launch highly specific, localized attacks against their distinct targets, making it a flexible tool for different campaigns.

Organizations should update their security software to track unusual behavior from developer tools, particularly the Deno software if it is not normally used by their employees. Additionally, network defenders can proactively hunt for the unique web traffic patterns identified by researchers to block connections to the attackers' servers.

About Affiliation
MuddyWater
MuddyWater is an Iranian MOIS-linked threat cluster active since at least 2017, formally attributed by US Cyber Command in 2022. The group conducts persistent espionage operations against government, telecommunications, defense, and energy sector targets across the Middle East, Central Asia, and Europe. MuddyWater is characterized by spear phishing with macro-enabled documents, heavy use of legitimate remote administration tools for post-compromise access, and custom PowerShell-based malware. It is tracked under numerous aliases including Seedworm, Mango Sandstorm, Mercury, TEMP.Zagros, Static Kitten, and TA450.
View MuddyWater's Insights