Researchers detailed a DinDoor backdoor campaign that delivers malware through MSI installers and abuses the legitimate Deno runtime to blend malicious activity with trusted software. Two analyzed samples, Installer_v1.21.66.msi and migcredit.pdf.msi, both fingerprint infected hosts and beacon to command-and-control infrastructure, but use different execution chains, payload delivery methods, and callback timing. One sample contacted serialmenot[.]com using a hardcoded JWT embedded in the C2 path, and decoded campaign metadata linked the infrastructure to activity previously associated with MuddyWater/Seedworm and CastleLoader.
The second sample used a double-extension lure likely themed around MigCredit and relied on obfuscated JavaScript with a separate C2 path and beacon interval. Hunt.io said distinctive HTTP response traits across the infrastructure enabled identification of 20 active DinDoor C2 servers spanning multiple autonomous systems. The findings suggest DinDoor is not tied to a single operator, but instead appears to function as a shared or multi-tenant malware platform used by multiple threat actors.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Based on differences between the samples and the spread of infrastructure, researchers concluded DinDoor likely operates as a shared or multi-tenant malware platform rather than being controlled by a single operator. This assessment was published in Hunt.io's analysis.
Using distinctive HTTP response characteristics associated with DinDoor infrastructure, researchers identified 20 active command-and-control servers across multiple autonomous systems. The findings suggested the malware was operating on broader shared infrastructure.
A separate sample, migcredit.pdf.msi, was identified using obfuscated JavaScript and a double-extension filename likely intended to lure MigCredit-related targets. It used a different C2 path and beacon interval from the other MSI sample.
Analysis of the Installer_v1.21.66.msi sample revealed a hardcoded JWT in its C2 path to serialmenot[.]com, exposing campaign metadata. The infrastructure overlap reinforced links to activity previously associated with MuddyWater/Seedworm and CastleLoader.
Two MSI-delivered DinDoor samples were observed installing or invoking the legitimate Deno runtime to execute a backdoor while fingerprinting infected hosts and communicating with command-and-control infrastructure. The samples differed in execution flow, payload delivery, and beaconing behavior, indicating multiple delivery variants within the campaign.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 39 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceinfosec.pub
Open sourcehunt.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.