#Dindoor
We discovered fake installers impersonating popular software including ChatGPT, Claude, AutoTune, and Kontakt on GitHub and SourceForge distributing a Deno backdoor known as DinDoor.

Attackers are using compromised YouTube channels to distribute links to the malicious software.
May 26, 2026 at 8:13 PM
Escalation in the Shadows: Iranian APT Seedworm Deploys ‘Dindoor’ Backdoor in New Cyberoffensive
Escalation in the Shadows: Iranian APT Seedworm Deploys 'Dindoor' Backdoor in New Cyberoffensive
Iranian APT Seedworm intensifies cyberespionage against US and Israeli networks using a new stealth backdoor called Dindoor. Read the full threat report.
securityonline.info
March 9, 2026 at 5:40 AM
Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor thehackernews.com/2026/03/iran...
Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor
Iran-linked MuddyWater hackers breached U.S. networks with new Dindoor malware as regional cyber attacks escalate amid Middle East conflict.
thehackernews.com
March 7, 2026 at 11:35 PM
Iran-linked MuddyWater deploys Dindoor malware against U.S. organizations
Iran-linked MuddyWater deploys Dindoor malware against U.S. organizations
Iran-linked APT MuddyWater targeted U.S. organizations, deploying the new Dindoor backdoor across sectors including banks, airports, and nonprofits.
securityaffairs.com
March 6, 2026 at 8:39 PM
Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor share.google/R52KJpKEL7Oi...
Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor
Iran-linked MuddyWater hackers breached U.S. networks with new Dindoor malware as regional cyber attacks escalate amid Middle East conflict.
share.google
March 7, 2026 at 6:06 PM
New research from Broadcom's Symantec and Carbon Black Threat Hunter Team has discovered evidence of an Iranian hacking group embedding itself in several U.S. companies' networks, including banks, airports, non-profit, and the Israeli arm of a software company. thehackernews.com/2026/03/iran...
Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor
Iran-linked MuddyWater hackers breached U.S. networks with new Dindoor malware as regional cyber attacks escalate amid Middle East conflict.
thehackernews.com
March 8, 2026 at 1:37 PM
Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor
Iran-Linked MuddyWater Hackers Target U.S. Networks With New Dindoor Backdoor
thehackernews.com
March 6, 2026 at 11:23 AM
eSentire's TRU looks into a malicious ClickFix-style command that installs DinDoor, a Deno-based loader, DenoRAT, a Deno-based Remote Access Trojan (RAT), and NightshadeC2, a sophisticated RAT and information stealer associated with TAG-150. www.esentire.com/blog/dindoor...
July 20, 2026 at 10:17 AM
Dindoor - The Technical Analysis of an Iranian Backdoor https://packetstorm.news/news/view/42942 #news
August 26, 2026 at 6:02 PM
Iran’s MuddyWater Hackers Target US Firms with New Dindoor Backdoor

Researchers say Iran's MuddyWater hackers targeted US companies and an Israeli software firm’s department in a cyber campaign using the Dindoor malware - All this amid the ongoing conflict.
#hackernews #news
Iran’s MuddyWater Hackers Target US Firms with New Dindoor Backdoor
Researchers say Iran's MuddyWater hackers targeted US companies and an Israeli software firm’s department in a cyber campaign using the Dindoor malware - All this amid the ongoing conflict.
hackread.com
March 10, 2026 at 9:23 AM
MuddyWater (Iran/MOIS) hit US infra with Dindoor + Fakeset. Donald Gay code-sign cert ties to Stagecomp/Darkcomp. Cloudflare rotation mapped hourly since March. https://www.dugganusa.com/post/muddywater-hit-us-infrastructure-with-dindoor-and-fakeset-we-ve-been-mapping-their-cloudflare-rotat
May 17, 2026 at 8:13 PM
Iranian-linked APT Seedworm intensifies cyberespionage targeting U.S. banks and defense-aerospace firms using a new backdoor called Dindoor. Hacktivist group Handala amplifies attacks with data leaks. #Seedworm #Dindoor #UnitedStates
Escalation in the Shadows: Iranian APT Seedworm Deploys ‘Dindoor’ Backdoor in New Cyberoffensive
The Threat Hunter Team reports a surge in cyberespionage by Iranian-linked APT Seedworm targeting multiple U.S. organizations and companies—often those with ties to Israel—since early February 2026. Researchers uncovered a previously undocumented backdoor named Dindoor across several victims, while hacktivist group Handala has used partial data leaks to amplify attacks, elevating...
www.hendryadrian.com
March 10, 2026 at 3:20 AM
Iran’s MuddyWater Hackers Hit US Firms with New 'Dindoor' Backdoor - Infosecurity Magazine www.infosecurity-magazine.com/news/iran-mu...
Iran’s MuddyWater Hackers Hit US Firms with New 'Dindoor' Backdoor
A bank, an airport, a non-profit and the Israeli branch of a US software company were among the targets of this new MuddyWater campaign
www.infosecurity-magazine.com
March 8, 2026 at 1:40 PM
Iran's MuddyWater hackers breached US organizations and an Israeli department of a software firm using phishing and a new backdoor dubbed #Dindoor - All this, despite the ongoing conflict.

Read: hackread.com/iran-muddywa...

#CyberSecurity #Iran #Israel #US #MuddyWater #Malware
Iran's MuddyWater Hackers Target US Firms with New Dindoor Backdoor
Follow us on all social media platforms @Hackread
hackread.com
March 9, 2026 at 2:28 PM
イラン系ハッカー集団、正規のDenoランタイムを悪用してWindowsシステムにDindoorバックドアを潜伏

MuddyWaterに関連するイラン系脅威アクターが、新たに確認されたWindowsバックドア「Dindoor」を使用しています。このマルウェアは正規のDenoランタイムを乗っ取り、悪意あるJavaScriptおよびTypeScriptペイロードを実行する仕組みです。 今回のキャンペーンは、信頼された開発者向けツール...
イラン系ハッカー集団、正規のDenoランタイムを悪用してWindowsシステムにDindoorバックドアを潜伏
MuddyWaterに関連するイラン系脅威アクターが、新たに確認されたWindowsバックドア「Dindoor」を使用しています。このマルウェアは正規のDenoランタイムを乗っ取り、悪意あるJavaScriptおよびTypeScriptペイロードを実行する仕組みです。 今回のキャンペーンは、信頼された開発者向けツール
blackhatnews.tokyo
August 26, 2026 at 10:33 AM
In early February 2026, the Iranian state-aligned cyber espionage group MuddyWater conducted a coordinated intrusion campaign targeting a small but strategically significant set of organizations across the United States, Israel, and Canada.

krypt3ia.wordpress.com/2026/03/20/t...
Threat Intelligence Report: MANGO SANDSTORM Dindoor / Fakeset Campaign
Date: March 2026By: Krypt3ia Executive Summary In early February 2026, the Iranian state-aligned cyber espionage group MuddyWater (also tracked as Seedworm, MERCURY, Static Kitten, MOIST KEYCH…
krypt3ia.wordpress.com
March 22, 2026 at 1:08 PM
Fake installers and plugins on GitHub and SourceForge impersonate ChatGPT, Claude, AutoTune, and Kontakt to deliver DinDoor and a Deno-based RAT, with compromised YouTube channels spreading malicious links. #Deno #GitHub #SourceForge
Fake software on GitHub and SourceForge distribute Deno RAT 
Attackers are abusing GitHub, SourceForge, and compromised YouTube channels to distribute fake installers and plugins impersonating popular software such as ChatGPT, Claude, AutoTune, and Kontakt. The campaign delivers DinDoor and a Deno-based RAT that uses alternative JavaScript runtimes, Scoop, and WinGet to install payloads, steal data, and hide traffic through Microsoft...
www.hendryadrian.com
May 27, 2026 at 1:00 AM
Iran's MuddyWater Just Dropped Two New Backdoors on U.S. Critical Infrastructure. Here's What We Know. open.substack.com/pub/cyberwar...
Iran's MuddyWater Just Dropped Two New Backdoors on U.S. Critical Infrastructure. Here's What We Know.
A technical breakdown of DinDoor and FakeSet — the latest weapons in Seedworm's rapidly expanding arsenal.
open.substack.com
March 6, 2026 at 8:48 PM
Fake ChatGPT and Claude installers on GitHub are dropping Deno RAT malware

Attackers are hosting counterfeit installers and plugins on GitHub and SourceForge that pose as widely used software, including ChatGPT, Claude, AutoTune, Kontakt, Ableton Live, and ZENOLOGY. The downl…
#chatgpt #claude #gpt
Fake ChatGPT and Claude installers on GitHub are dropping Deno RAT malware
Attackers are hosting counterfeit installers and plugins on GitHub and SourceForge that pose as widely used software, including ChatGPT, Claude, AutoTune, Kontakt, Ableton Live, and ZENOLOGY. The downloads deliver a backdoor called DinDoor, which then loads a remote access Trojan built on the Deno JavaScript runtime, according to Malwarebytes. Compromised YouTube channels push victims toward the malicious repositories. The videos promoting the fake tools have accumulated more than 50,000 views. The attackers rotate through GitHub …
www.helpnetsecurity.com
May 28, 2026 at 7:37 AM
O grupo de ciberespionagem iraniano conhecido como MuddyWater (ou Seedworm) foi dado como estando envolvido em operações de intrusão contra redes nos EUA, incluindo bancos e aeroportos, utilizando uma nova backdoor chamada Dindoor.
O APT iraniano MuddyWater está ativo nos EUA (e, provavelmente, também na Europa)
O grupo de ciberespionagem iraniano conhecido como MuddyWater (ou Seedworm) foi dado como estando envolvido em operações de intrusão contra redes nos EUA, incluindo bancos e aeroportos, utilizando …
cidadaospelaciberseguranca.com
March 10, 2026 at 8:30 PM
Dindoor - The Technical Analysis of an Iranian Backdoor
Dindoor is a backdoor that abuses the Deno runtime to execute malware within a target environment. Rather than shipping its own interpreter, Dindoor relies on Deno, a legitimate and widely used JavaScript and TypeScript runtime, and will install that runtime on the victim machine on demand if it is not already present. Few of its individual components are novel; what makes Dindoor effective is the combination of a signed third-party runtime performing execution, base64 encoding at every stage, and an environment check that must pass before the backdoor establishes persistence. After initial staging, the loader confirms whether the Deno runtime is present on the victim machine and, if it is not, downloads it from deno.land via curl.exe. What does not change between builds is the behavior beneath the encoding, and that is where detection must focus: deno.exe launching with a lengthy base64 argument on a host with no developer profile curl.exe reaching out to deno.land on a machine with no legitimate reason to install a JavaScript runtime a Run key directing wscript.exe to a VBScript within a subdirectory of AppData\Local a `Win32_VideoController` WMI query originating from a PowerShell process spawned by cmd.exe Binary Defense researchers developed hypothesis-based threat hunting queries around these patterns, targeting the fixed structure of Dindoor's execution chain rather than the encoded contents that change with each build. By adopting a mainstream developer runtime as its execution engine, MuddyWater gains a legitimate signed binary, a network destination few organizations have reason to block, and a script format that most detection content was never written to address.
binarydefense.com
August 28, 2026 at 11:56 PM
August 26, 2026 at 2:01 PM