Deno is a tool tracked by ThreatCluster, appearing in 9 threat clusters built from 16 intelligence report mentions.
Deno is a tool tracked across 9 threat clusters and 16 intelligence report mentions on ThreatCluster. First observed March 10, 2026; most recent activity July 22, 2026.
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
A malicious campaign named Solana FakeFix is targeting Solana developers by deploying 25 typosquatted npm and PyPI packages. These packages are designed to steal sensitive information such as wallet keys, cloud…
LeakNet, a ransomware group, has adopted new tactics involving ClickFix social engineering and a Deno-based fileless loader. This shift allows them to gain initial access through compromised websites, prompting users to…
A newly identified backdoor, DinDoor, exploits the Deno JavaScript runtime and MSI installer files to execute malicious code while avoiding detection. This malware is associated with the Tsundere Botnet and leverages…
A new Remote Access Trojan (RAT) utilizing the Deno JavaScript runtime has been deployed against employees through email flooding and fake Microsoft Teams calls. The attack combines social engineering tactics to…
A new cyberattack known as CastleRAT has emerged, utilizing the Deno JavaScript runtime to bypass enterprise security defenses. The attack primarily targets organizations using Deno for application development,…
Following U.S. military strikes on Iran, there is an anticipated increase in cyber warfare activities targeting U.S. operational technology and critical infrastructure. Iran is expected to retaliate with cyber attacks…
A new cyber attack has been identified that exploits the Deno JavaScript runtime to deliver fileless malware. This incident marks the first known use of Deno in such a malicious context, raising concerns among…
A critical vulnerability in Axios, tracked as CVE-2026-40175, was reported with a CVSS score of 9.9, suggesting potential for remote code execution (RCE) and cloud infrastructure compromise. However, analysis reveals…
Deno is a tool tracked by ThreatCluster, appearing in 9 threat clusters built from 16 intelligence report mentions.
The most recent intelligence report mentioning Deno on ThreatCluster is dated July 22, 2026. Activity was first observed March 10, 2026, giving a tracked span from then to July 22, 2026.
Across ThreatCluster reporting, Deno most frequently co-occurs with Apt34, APT42, MuddyWater, Prince Of Persia, UNK_SmudgedSerpent, among 12 tracked related entities.
The most significant recent cluster is “MuddyWater Targets U.S. Entities Amid Geopolitical Tensions” (16 articles · Updated July 22, 2026). Deno appears across 9 threat clusters in total, listed above with sources.
Deno appears in 16 intelligence report mentions across 9 deduplicated threat clusters, aggregated from 17,000+ monitored sources.