DinDoor Malware Exploits Deno Runtime to Target US and Russian Entities
- Actor Motivations: Espionage,Exfiltration,Extortion,Financial Gain
- Attack Vectors: Backdoor,Botnet,Downloader,Fileless malware,Ransomware,Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/High Probability
Threat Overview
DinDoor, a modular Tsundere botnet variant linked to state-sponsored actors like MuddyWater and cybercrime clusters, exploits the Deno runtime to execute obfuscated JavaScript, effectively bypassing traditional endpoint detections. Delivered via deceptive MSI files, recent campaigns have targeted U.S. organizations and the Russian financial services sector. Upon execution, the malware binds a local port as a mutex, aggressively fingerprints the victim’s hardware, and communicates with a multi-tenant command and control (C2) infrastructure, notably serialmenot[.]com. By analyzing unique Caddy proxy HTTP response headers, researchers identified 20 active C2 servers. Ultimately, DinDoor demonstrates how threat actors increasingly abuse trusted, signed runtimes and shared backend platforms to conceal their operations.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Case | MigCredit MigCredit is a prominent microfinance organization (MFO) that operates primarily in Russia. MigCredit has been targeted by MuddyWater as the main target. | Verified |
| Sector | Financial | Verified |
| Region | Russia | Verified |
| Region | United States | Verified |
Extracted IOCs
- aeeracaspsl[.]site
- annaionovna[.]com
- bitatits[.]surf
- hngfbgfbfb[.]cyou
- ilspaeysoff[.]site
- ineracaspsl[.]site
- justtalken[.]com
- landmas[.]info
- myspaeysoff[.]site
- playerdragonbike[.]com
- weaplink[.]com
- bandage.healthydefinitetrunk[.]com
- generalnewlong.comagilemast3r.duckdns[.]org
- grafana.healthydefinitetrunk[.]com
- surgery.healthydefinitetrunk[.]com
- 2a09bbb3d1ddb729ea7591f197b5955453aa3769c6fb98a5ef60c6e4b7df23a5
- 7b793c54a927da36649eb62b9481d5bcf1e9220035d95bbfb85f44a6cc9541ae
- 138[.]124.240.76
- 138[.]124.240.77
- 140[.]82.18.48
- 146[.]19.254.84
- 178[.]104.137.180
- 178[.]16.52.191
- 185[.]218.19.117
- 192[.]109.200.151
- 193[.]233.82.43
- 193[.]24.123.25
- 194[.]48.141.192
- 199[.]217.99.189
- 199[.]91.220.142
- 199[.]91.220.216
- 209[.]99.189.170
- 2[.]26.117.169
- 2[.]27.122.16
- 45[.]135.180.200
- 45[.]151.106.88
- 85[.]192.27.152
Tip: 37 related IOCs (20 IP, 15 domain, 0 URL, 0 email, 2 file hash) to this threat have been found.
Overlaps
Source: Check Point - March 2026
Detection (one case): 2a09bbb3d1ddb729ea7591f197b5955453aa3769c6fb98a5ef60c6e4b7df23a5
Source: Symantec - March 2026
Detection (one case): 2a09bbb3d1ddb729ea7591f197b5955453aa3769c6fb98a5ef60c6e4b7df23a5
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Understanding the DinDoor Malware Threat
Cybersecurity researchers discovered a malware family named DinDoor that is compromising computers by hijacking a legitimate developer application called Deno. By analyzing the unique way the attackers configured their web servers, investigators were able to expose 20 active control servers managing the malware across the internet.
The infrastructure running DinDoor is shared among multiple threat actors operating on a "Malware-as-a-Service" model. Evidence links this shared platform to state-sponsored groups like the Iranian-aligned Seedworm (also known as MuddyWater), as well as financially motivated cybercrime groups.
The primary goal is to establish a hidden, persistent backdoor on a victim's system. Once installed, the malware generates a unique fingerprint of the computer, checks to ensure it isn't running in a security researcher's test environment, and quietly waits for further malicious commands or payloads from the attackers.
Targeting depends heavily on which specific threat group is using the shared platform at a given time. For instance, one discovered attack was disguised as a document from a Russian microloan company, indicating targeted financial espionage, while other campaigns using this malware have historically focused on U.S. organizations.
Attackers trick users into opening deceptive installation files, sometimes disguised as simple PDF documents. When opened, these files might show a fake error message to confuse the user, while secretly downloading a runtime tool and executing hidden malicious scripts directly into the computer's memory.
Because the platform is used by both state-sponsored spies and cybercriminals, victims are attractive for different reasons. Government-backed actors use it to steal sensitive organizational data and intellectual property, while cybercriminals use it to establish a foothold for financial extortion or ransomware deployment.
It is a targeted threat utilizing a widespread, shared infrastructure. Various hacking groups rent or share the underlying technology to launch highly specific, localized attacks against their distinct targets, making it a flexible tool for different campaigns.
Organizations should update their security software to track unusual behavior from developer tools, particularly the Deno software if it is not normally used by their employees. Additionally, network defenders can proactively hunt for the unique web traffic patterns identified by researchers to block connections to the attackers' servers.