Iran
Iran-linked operators are using a trusted developer tool to conceal a backdoor called Dindoor inside Windows environments. The malware uses the Deno JavaScript and TypeScript runtime to execute encoded code, helping its activity blend into legitimate software use. Dindoor has appeared as a later-stage payload in spearphishing intrusions. Researchers observed it at U.S. software and […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
