DinDoor Backdoor: Deno Runtime Abuse and 20 Active C2 Servers
hunt.io | blog | #threat-intelligence | #malware | #backdoor | #command-and-control | #dindoor | #deno | #tsundere | #muddywater
Summary
Hunt.io dissects DinDoor, a Tsundere-variant backdoor abusing the Deno runtime: MSI-delivered obfuscated JavaScript, a hardcoded JWT leaking campaign data, and a pivot to 20 active C2 servers.
- Published
- Collected
Skip to content