DinDoor is a Deno-based JavaScript and TypeScript backdoor and multi-stage stager associated with Iranian MOIS-linked MuddyWater, also tracked as Seedworm. It has been used against Windows environments in espionage and pre-positioning activity affecting financial, transportation, defense-adjacent software, and nonprofit organizations in the United States, Israel, and Canada. DinDoor abuses the legitimate Deno runtime to execute encoded or obfuscated code, profile compromised hosts, communicate with command-and-control infrastructure, and retrieve further-stage payloads. It can establish Windows Run-key persistence and uses virtual-environment checks to reduce execution in analysis environments. Campaigns have delivered it through targeted social engineering, including Microsoft Teams impersonation, ClickFix lures, and counterfeit software installers and plugins distributed through trusted developer platforms and promoted by compromised social-media accounts. DinDoor commonly serves as the initial loader for more capable Deno-based remote-access payloads that support remote command execution, browser and cryptocurrency-wallet data theft, screenshot capture, SOCKS5 proxying, and remote desktop-style control.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Iran-linked operators are using a trusted developer tool to conceal a backdoor called Dindoor inside Windows environments. The malware uses the Deno JavaScript and TypeScript runtime to execute encoded code.
Symantec named the Deno based JavaScript malware “DinDoor” and attributed it to MuddyWater.
The campaign, publicly disclosed in early March 2026, leveraged two malware families Dindoor, a backdoor utilizing the Deno runtime, and Fakeset, a Python-based implant alongside legitimate tooling and cloud infrastructure to establish persistent access and enable data exfiltration.
The group deployed two malware, a newly discovered backdoor called Dindoor and a Python-based tool called Fakeset, across multiple victim environments.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
The infection begins when a user visits a malicious GitHub or SourceForge repository and copies a command into their terminal, believing they are installing legitimate software.
“Dindoor has appeared as a later-stage payload in spearphishing intrusions” and “The infection begins after an earlier phishing stage places its loader on a device.”
“The final stage first checks the machine’s graphics adapter through a PowerShell Windows Management Instrumentation query.”
The observed activity maps to several established ATT&CK techniques, including spearphishing for initial access, command and scripting interpreter abuse (expanded to include Deno)
Then, the MSI file writes and executes a Windows batch file. This batch file launches an artificial intelligence-generated PowerShell script named Griffin20.ps1.
“It creates a Windows Run registry entry that launches a VBScript through wscript.”
“The malware uses the Deno JavaScript and TypeScript runtime to execute encoded code” and “launches it with a long Base64-encoded argument containing the Dindoor code.”
The attack begins with a ClickFix-style social engineering lure. Specifically, the attackers trick a victim into executing a command via the Windows Run prompt. | Specifically, the attackers trick a victim into executing a command via the Windows Run prompt. This command downloads and runs a Microsoft Installer (MSI) file.
“Dindoor combines a signed runtime, Base64 encoding, and checks that evade analysis” and “the data is Base64-encoded to hide its contents.”
Through this interaction, the user was convinced to execute a malicious installer named update_ms.msi, masquerading as a Windows update package.
The observed activity maps to several established ATT&CK techniques, including spearphishing for initial access, command and scripting interpreter abuse (expanded to include Deno), ingress tool transfer via cloud-hosted payloads, exfiltration over web services using Rclone, and application-layer command-and-control mechanisms.
“Dindoor’s network communications use Deno’s listen function to create a TCP listener.”
98 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
48 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multi-stage Windows backdoor attributed to MuddyWater that abuses the signed Deno runtime to execute Base64-encoded payloads. It gathers host information, communicates with a remote server, retrieves subsequent stages, checks graphics adapters for virtualized or automated-analysis environments, and persists through a Windows Run registry entry that launches a VBScript via wscript.
A Deno-delivered stager/backdoor component that continuously polls C2 to fetch a secondary stager, helping establish the next stage of the intrusion.
Related coverage Escalation in the Shadows: Iranian APT Seedworm Deploys ‘Dindoor’ Backdoor in New Cyberoffensive
A Deno-based loader that fetches and executes the next-stage stager from C2 via eval(). It is used early in the ClickFix infection chain and supports persistence indirectly by being re-fetched and written to disk by the next stage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.