Iran-linked MuddyWater operators have used the Dindoor backdoor after spearphishing compromises of Windows environments, targeting U.S. software and banking organizations and a Canadian non-profit. The malware abuses the legitimate signed deno.exe JavaScript and TypeScript runtime to execute Base64-encoded payloads, reducing the effectiveness of static and hash-based detections.
The multi-stage chain inventories infected hosts, contacts a remote server, and checks for virtualized analysis environments, including PowerShell queries of Win32_VideoController to identify graphics hardware. Persistence is established through a Windows Run registry key that launches a VBS file—reported as SerialLynx_system59.vbs under a local AppData path—via wscript.exe; defenders should investigate anomalous Deno execution, unapproved Deno downloads using curl.exe, script-host activity, and Run keys invoking scripts from AppData Local.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
Binary Defense began tracking the Dindoor backdoor and attributed the activity to the Iran-linked MuddyWater threat group. The backdoor was used as a later-stage payload following spearphishing-based intrusions targeting U.S. software and banking organizations and a Canadian non-profit.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.