DinDoor is a Windows backdoor that abuses the legitimate Deno JavaScript and TypeScript runtime to execute staged, often obfuscated payloads while blending with trusted software activity. It has been described as a Deno-based backdoor and loader, and some reporting tracks it as a variant of the Tsundere botnet. DinDoor commonly arrives through MSI-based installers and social-engineering lures, including fake software installers and plugins, deceptive update packages, collaboration-platform impersonation, and malicious repositories hosted on trusted developer platforms. Observed lures have impersonated popular AI tools, creative software, and enterprise support workflows, and campaigns have also used ClickFix-style user execution chains.
Once executed, DinDoor typically installs or locates the Deno runtime, launches JavaScript in memory or from staged files, fingerprints the host, establishes command-and-control communications, and retrieves follow-on payloads. Multiple observed chains show DinDoor acting as an initial backdoor or launcher that fetches additional stages via repeated remote code retrieval and evaluation. Persistence has been established through Windows Run-key mechanisms. Reported behavior includes host registration, system reconnaissance, payload staging, and delivery of more capable remote-access tooling. In several campaigns, DinDoor served as the precursor to a Deno-based RAT with broader capabilities such as command execution, screenshot capture, browser and cryptocurrency-wallet data theft, proxying, and remote desktop-style control.
DinDoor has been linked in multiple investigations to Iranian state-aligned activity, especially MuddyWater, also tracked as Seedworm and associated with Iran’s Ministry of Intelligence and Security. Reported targeting has included organizations in the United States, Israel, and Canada, including financial institutions, transportation entities, defense-adjacent organizations, software suppliers, and nonprofits. Separate criminal-style distribution activity has also used fake installers on GitHub, SourceForge, and similar platforms to target creators, gamers, AI enthusiasts, and other users likely to run unofficial software. Some infrastructure and certificate overlaps have also been noted with broader malware ecosystems and shared backend services, indicating that DinDoor-related operations may span both state-linked intrusion sets and cybercrime-style delivery channels.
The malware’s operational value lies in its use of trusted runtimes, in-memory execution patterns, and low-signature staging behavior, which can reduce conventional detection opportunities. Across documented intrusions, DinDoor has been used for persistent access, reconnaissance, payload delivery, and enabling downstream data theft and exfiltration operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Further investigation found that the command installs DinDoor, a Deno-based loader... DinDoor, also known internally as "launcher-1", is a tiny eval-loop that fetches launcher-2...
Related coverage Escalation in the Shadows: Iranian APT Seedworm Deploys ‘Dindoor’ Backdoor in New Cyberoffensive
The campaign, publicly disclosed in early March 2026, leveraged two malware families Dindoor, a backdoor utilizing the Deno runtime, and Fakeset, a Python-based implant alongside legitimate tooling and cloud infrastructure to establish persistent access and enable data exfiltration.
The group deployed two malware, a newly discovered backdoor called Dindoor and a Python-based tool called Fakeset, across multiple victim environments.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
The infection begins when a user visits a malicious GitHub or SourceForge repository and copies a command into their terminal, believing they are installing legitimate software.
The observed activity maps to several established ATT&CK techniques, including spearphishing for initial access, command and scripting interpreter abuse (expanded to include Deno)
The chain then leveraged a likely AI-generated PowerShell stage to install the Deno runtime and launch the next-stage Deno-based loader, DinDoor.
The MSI file then drops a CMD file and a PowerShell script onto the victim’s machine.
The DenoRAT stager, also known internally as, "launcher-2" is obfuscated via Obfuscator.io
Through this interaction, the user was convinced to execute a malicious installer named update_ms.msi, masquerading as a Windows update package.
This RAT can steal data from browsers and crypto wallets... It targets over 50 crypto wallet browser extensions and software wallets including Atomic Wallet, Exodus, and Electrum...
This RAT can steal data from browsers and crypto wallets, capture screenshots...
The observed activity maps to several established ATT&CK techniques, including spearphishing for initial access, command and scripting interpreter abuse (expanded to include Deno), ingress tool transfer via cloud-hosted payloads, exfiltration over web services using Rclone, and application-layer command-and-control mechanisms.
96 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
45 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Related coverage Escalation in the Shadows: Iranian APT Seedworm Deploys ‘Dindoor’ Backdoor in New Cyberoffensive
A Deno-based loader that fetches and executes the next-stage stager from C2 via eval(). It is used early in the ClickFix infection chain and supports persistence indirectly by being re-fetched and written to disk by the next stage.
A purported Seedworm backdoor that reportedly uses the Deno runtime for execution and may be signed with the certificate 'Amy Cherne'.
A backdoor delivered via fake ChatGPT and Claude installers hosted on GitHub and SourceForge repositories impersonating legitimate software distributions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.