ThreatCluster

Iran-Linked Threat Actors Deploy Dindoor Backdoor via Deno Runtime

First seen 26 Aug 2026, 17:36 UTC CybersecuritynewsGbhackers 73

Article Content

Browse articles
ThreatCluster

Iran-linked threat actors associated with MuddyWater are exploiting a Windows backdoor named Dindoor. This malware utilizes the legitimate Deno runtime to execute malicious JavaScript and TypeScript payloads, making detection challenging. Dindoor has been observed as a later-stage payload in spearphishing attacks targeting U.S. software companies. The campaign highlights the risks of trusted developer tools being misused for malware execution, complicating traditional detection methods. The full scope of the impact remains unclear, but the use of legitimate software for malicious purposes raises significant security concerns. Organizations using Deno or similar developer tools should be vigilant and enhance their monitoring capabilities.

Key Points: • Dindoor backdoor exploits the Deno runtime for malicious payload execution. • The malware is linked to Iranian threat actors, specifically the MuddyWater group. • Dindoor has been identified in spearphishing campaigns targeting U.S. software companies.

Timeline

2026-08-26
Dindoor backdoor reported
Iran-linked actors use Dindoor to hijack the Deno runtime for executing malicious code.
Gbhackers
2026-08-26
Spearphishing campaigns observed
Dindoor has been detected as a later-stage payload in targeted spearphishing attacks against U.S. software firms.
Cybersecuritynews