Iran-linked operators are using a trusted developer tool to conceal a backdoor called Dindoor inside Windows environments. The malware uses the Deno JavaScript and TypeScript runtime to execute encoded code, helping its activity blend into legitimate software use. Dindoor has appeared as a later-stage payload in spearphishing intrusions. Researchers observed it at U.S. software and banking organizations and at a Canadian non-profit, demonstrating its reach across different sectors. Analysts at Binary Defense began tracking the backdoor in early 2026 and linked the activity to MuddyWater, an Iranian threat group. Binary Defense said in a report shared with Cyber Security News (CSN) that Dindoor combines a signed runtime,...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!