Skip to content
Deno-Based RAT Leveraging Teams Impersonation Targets Employees

Deno-Based RAT Leveraging Teams Impersonation Targets Employees

First seen 17 Jun 2026, 17:10 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 18, 2026 at 16:45 UTC
  • A Deno-based RAT is being deployed through email flooding and Teams impersonation.
  • The malware operates using modular JavaScript files with specific permission flags.
  • Organizations should implement monitoring for Deno executions and Teams impersonation alerts.

A new Remote Access Trojan (RAT) utilizing the Deno JavaScript runtime has been deployed against employees through email flooding and fake Microsoft Teams calls. The attack combines social engineering tactics to overwhelm targets, leading to the download of a malicious archive. The malware operates via multiple modular JavaScript files and uses specific Deno permission flags for command and control communication. Detection occurred during post-exploitation activities rather than initial execution. Organizations are advised to monitor for suspicious Deno executions and Teams impersonation alerts. The attack's scope appears to be significant, affecting multiple organizations. Immediate isolation of affected hosts is recommended upon detection.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 94d ago How this analysis works

Timeline

2026-06-17
Deno-based RAT discovered
Researchers identified a RAT using Deno, targeting employees via email flooding and fake Teams calls.
Cybersecuritynews
2026-06-17
Attack methodology detailed
The attack employs social engineering tactics and modular scripts for C2 communication and command execution.
Socprime

More articles in this cluster (2)