Attackers used a mailbombing campaign and Microsoft Teams impersonation to trick an employee into downloading a malicious archive from a fake self-service portal, deploying a modular remote access trojan built on the Deno runtime. Researchers said the malware consisted of four heavily obfuscated JavaScript files—app.js, back.js, helper.js, and webui.js—that split functions across processes using Deno permission flags, established persistence through the HKCU\Run registry key, and communicated with a CloudFront-hosted WebSocket command-and-control endpoint to blend with legitimate traffic.
The intrusion gave operators remote command execution through cmd.exe, used conhost.exe --headless to reduce visibility, and exposed loopback services that enabled TCP tunneling and internal network pivoting from the compromised host. Endpoint protection reportedly did not block the implant or its C2 traffic at launch, and detection came later during reconnaissance activity including LDAP and certificate-related queries, prompting recommendations to monitor Deno execution from user-writable paths, suspicious permission flags, loopback listeners, registry persistence, and correlations between external Teams calls and sudden email floods.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
On June 4, 2026, InfoGuard Labs published a report detailing the intrusion chain, the four-module Deno malware architecture, persistence, command execution, tunneling behavior, and behavioral detection opportunities.
Endpoint protection did not initially block or flag the implant or its command-and-control traffic. Detection occurred later when the attacker conducted reconnaissance activity including LDAP queries and certificate-related queries.
After execution, the malware ran as four obfuscated JavaScript modules on the Deno runtime, used Deno permission flags to separate functions, created persistence via the HKCU Run key, and connected to a CloudFront-hosted WebSocket command-and-control endpoint. It also exposed loopback services for command execution and TCP tunneling to support remote control and pivoting.
Attackers flooded victims with emails and then used an external Microsoft Teams account impersonating internal IT support to socially engineer at least one employee into downloading a malicious archive from a fake self-service portal. The delivered payload was a modular Deno-based remote access trojan and proxy framework.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.