Deno-Based RAT Leveraging Teams Impersonation Targets Employees

Deno-Based RAT Leveraging Teams Impersonation Targets Employees

First seen 17 Jun 2026, 17:10 UTC CybersecuritynewsSocprime 71% similarity 64.5

Article Content

Browse articles
ThreatCluster

A new Remote Access Trojan (RAT) utilizing the Deno JavaScript runtime has been deployed against employees through email flooding and fake Microsoft Teams calls. The attack combines social engineering tactics to overwhelm targets, leading to the download of a malicious archive. The malware operates via multiple modular JavaScript files and uses specific Deno permission flags for command and control communication. Detection occurred during post-exploitation activities rather than initial execution. Organizations are advised to monitor for suspicious Deno executions and Teams impersonation alerts. The attack's scope appears to be significant, affecting multiple organizations. Immediate isolation of affected hosts is recommended upon detection.

Key Points: • A Deno-based RAT is being deployed through email flooding and Teams impersonation. • The malware operates using modular JavaScript files with specific permission flags. • Organizations should implement monitoring for Deno executions and Teams impersonation alerts.

ThreatCluster AI How this analysis works

Timeline

2026-06-17
Deno-based RAT discovered
Researchers identified a RAT using Deno, targeting employees via email flooding and fake Teams calls.
Cybersecuritynews
2026-06-17
Attack methodology detailed
The attack employs social engineering tactics and modular scripts for C2 communication and command execution.
Socprime

Community

Browse all →